Core Lightning has urged node operators running version 26.06.7 or earlier to update immediately after receiving reports that attackers are going after unpatched systems on the Bitcoin Lightning Network.

The project did not disclose which weaknesses are being targeted or spell out the full impact of the attacks. Still, it tied the warning to security fixes shipped in version 26.06.8, a release published on Sept. 22 after the team said it was examining a potential issue linked to experimental features.

Immediate warning for older releases

In a Friday notice, the Core Lightning team described the update as urgent and said anyone still using version 26.06.7 or below should move to the latest release as soon as possible. The software is an open-source implementation for running Lightning Network nodes on Bitcoin.

The maintainers did not identify the exact vulnerabilities now being exploited, and they did not detail how widespread the reported attacks may be. That leaves some uncertainty around the scope of the threat, but the public guidance was unambiguous: older versions should be considered exposed until upgraded.

What changed in version 26.06.8

Version 26.06.8 was released roughly six days after Core Lightning said on Sept. 16 that it was investigating reports of a possible issue involving experimental features that could affect user funds.

According to the release notes, the Sept. 22 update included general bug fixes as well as patches for vulnerabilities that had been responsibly reported. The changelog credits the Bitcoin Red Team, 12 other named people and groups, and anonymous reporters for helping identify the issues.

Among the fixed problems were bugs that could crash sender nodes, requests that could exhaust memory through the REST interface, and a channel-closing flaw that could lead to a penalty and loss of funds for users.

Why some details were withheld

Core Lightning said it intentionally left out certain tests from the public release in order to make it more difficult for attackers to reverse-engineer the flaws while node operators were still upgrading.

That approach suggests the team viewed the patched issues as sensitive enough that fully publishing technical details immediately could increase risk for users who had not yet updated. At the same time, the project has not publicly linked the current reports of attacks to any one disclosed bug.

Recent security work and next step

The latest warning follows earlier security work in August, when Core Lightning said it was preparing a coordinated fix after reviewing a large number of AI-generated Common Vulnerabilities and Exposures reports submitted over recent weeks.

Two days after that notice, the project released version 26.06.7 to address the vulnerabilities it had confirmed at the time. The next confirmed step now is straightforward: operators on 26.06.7 or any earlier version have been told to upgrade to the newest release as quickly as possible while the team keeps technical specifics limited.

Source: cointelegraph.com