Core Lightning Warns Unpatched Bitcoin Nodes Face Active Attacks
The open-source Lightning node team says attackers are targeting outdated versions and urges immediate upgrades.
Key takeaways
- Affected versions are 26.06.7 and older. Nodes running version 26.06.7 or earlier are vulnerable to active attacker targeting.
- Patch released September 22. The fixed version 26.06.8 launched on September 22 with security patches.
- No confirmed fund losses yet. Core Lightning has not confirmed any user fund losses from the reported attacks.
What happened
On October 2, 2026, the Core Lightning development team issued an urgent security alert for Bitcoin Lightning Network node operators. The team said it had received reports of attackers actively targeting nodes running outdated software, and urged all operators of affected versions to upgrade to the latest release immediately. Core Lightning did not share details about the specific vulnerabilities being exploited in the active attacks, nor did it confirm whether any reported incidents have led to user fund losses.
The alert follows a series of security updates from the project in recent months. In August 2026, Core Lightning confirmed it was addressing a high volume of AI-generated vulnerability reports, and released version 26.06.7 two days later to patch confirmed issues. On September 16, the team announced it was investigating a potential problem linked to experimental features that could impact user funds, and launched the patched version 26.06.8 six days later on September 22.
Why it matters
The unpatched vulnerabilities pose direct risks to node operators and Lightning Network users. The September 22 patch fixed flaws that could crash sender nodes, exhaust memory in the software's REST interface, and trigger a channel-closing bug that could cause users to lose funds to penalty transactions. To reduce exploitation risk while operators upgraded, the Core Lightning team deliberately withheld some test cases from the public release, making it harder for attackers to reverse-engineer the underlying flaws.
What is still unclear
- Core Lightning has not confirmed whether the active attacks are exploiting the vulnerabilities patched in the September 22 update, or a separate set of flaws affecting older versions.
Questions readers ask
What Core Lightning versions are affected by the active attacks?
Core Lightning has confirmed that nodes running version 26.06.7 or earlier are at risk. Operators of these versions are urged to upgrade to the latest release immediately.
Has any user lost funds from the targeted Core Lightning attacks?
As of the October 2 alert, Core Lightning has not disclosed whether any of the reported attacks have resulted in lost user funds.
When was the patched Core Lightning version released?
The patched version 26.06.8 was released on September 22, 2026, with fixes for multiple security vulnerabilities.
Sources · 5 publishers
-
Core Lightning warns attackers are targeting unpatched Bitcoin nodes
-
Bitcoin Lightning security alert issued as attackers target older Core Lightning nodes -
Core Lightning Nodes Under Attack: Bitcoin Developers Urge Immediate Upgrade -
Core Lightning Warns Bitcoin Node Operators to Upgrade After Attack Reports -
Bitcoin Lightning Nodes Targeted as Core Lightning Sounds Alarm