Core Lightning has told node operators using version 26.06.7 or earlier to upgrade immediately after reports of attacks on unpatched nodes. The project has not named the vulnerabilities being targeted, so node holders cannot yet judge whether their funds are at risk.
Core Lightning is open-source node software for the Bitcoin Lightning Network. Version 26.06.8 is the current upgrade recommended for operators running an older release.
Version 26.06.8 Fixes Several Serious Flaws
Core Lightning began investigating a possible problem with experimental features on Sept. 16 after reports that it could affect user funds. It released version 26.06.8 about six days later, on Sept. 22.
The release notes say the update addressed several issues:
- Flaws that could crash a sender’s node.
- Requests that could exhaust memory through the REST interface.
- A channel-closing bug that could cause users to lose funds through a penalty.
The project also withheld a small number of tests to make the vulnerabilities harder to identify and exploit while operators upgraded.
The Urgent Warning Does Not Name the Exploits
Core Lightning did not specify which vulnerabilities the reported attackers are targeting. It also did not explain what an attack could achieve, whether any systems have been compromised or whether the September fund-risk investigation is connected.
That leaves an important gap for Lightning users. A node operator can act on the upgrade instruction, but cannot use the project’s warning to confirm whether a particular attack has affected their node or funds.
The project strongly recommends upgrading and says the fixes in version 26.06.8 were available immediately without an embargo.
Development Builds Cannot Downgrade
Operators running master or development builds cannot move back to the 26.06.x series because their database schema is newer. They need to remain on a compatible development release while upgrading.
The release notes also keep two warnings in place. Dual funding through --experimental-dual-fund remains experimental, and zero-confirmation channels with untrusted peers are discouraged.
For most operators, the practical response is direct: check the installed version and move to 26.06.8 or a later release. The unresolved issue is what prompted the reported attacks in the first place, and Core Lightning has not yet supplied enough information to answer that.
The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.
Copyright Altcoin Buzz Pte Ltd.
