Meta Force Space
BTC $85,990.00 +2.01% ETH $2,725.11 +0.32% SOL $121.65 +1.89% XRP $1.52 +1.09% BNB $777.42 +0.82% DOGE $0.0958 +0.08%
← Back to the news

Core Lightning warns attackers are targeting unpatched nodes

Written by Felix Ngstaff editorReviewed by Yohan Yunstaff editor
Written by Felix Ngstaff editor
Reviewed by Yohan Yunstaff editor
Core Lightning warns attackers are targeting unpatched Bitcoin nodes
Latest NewsPublishedOct 2, 2026

Node operators running version 26.06.7 or earlier were told to upgrade immediately.

The team behind Core Lightning, an open-source node software for the Bitcoin Lightning Network, has urged operators running older versions to upgrade immediately after receiving reports of attackers targeting unpatched nodes.

“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said on Friday.

Core Lightning did not specify which vulnerabilities attackers were targeting or the potential impact. Cointelegraph reached out to Core Lightning for comment.

Source: Blockstream

On Sept. 16, Core Lightning said it was investigating reports of a potential issue affecting experimental features in Core Lightning that could impact user funds. It then released version 26.06.8 around six days later.

The Sept. 22 update delivered bug fixes alongside patches for “vulnerabilities responsibly reported by a number of sources.” The release notes credit the Bitcoin Red Team and 12 other named individuals and groups, along with anonymous reporters.

Some of the fixes addressed flaws that could crash senders’ nodes, requests that could exhaust memory in its REST interface and a channel-closing bug that could cause users to lose funds to a penalty, according to the changelog.

However, the release deliberately withheld some tests to make it harder for attackers to reverse-engineer and exploit vulnerabilities while operators upgraded.

In August, Core Lightning said it was working on a coordinated fix after assessing a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports over recent weeks.

Two days later, it released 26.06.7 to address the confirmed vulnerabilities.

Related: Core Lightning confirms multiple vulnerabilities, prepares security update

1 minute letter1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

More on the subject

Originally published by Cointelegraph on

Read the original on Cointelegraph ↗

Text and images are the property of Cointelegraph and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news