Core Lightning is preparing a point security release, v26.06.7, with project contributor Christian Decker saying the update is expected within about 24 hours. According to the advance notice, no vulnerability is known to be under active exploitation.

The release will follow an unusual publication process aimed at limiting the value of reverse-engineering the fix. Binaries are set to be published immediately, while the source code will be withheld for 14 days and released later for verification through Core Lightning’s reproducible build system.

Planned release and disclosure timeline

The project described the upcoming update as an embargoed security release rather than a routine point upgrade. Under the plan outlined by Decker, users will be able to install published binaries first, with the corresponding source code disclosed two weeks later.

Core Lightning said that once the source becomes public, users will be able to check that the released binaries match the code by using the project’s reproducible build process. The stated goal of delaying source publication is to make it harder for attackers to quickly infer the underlying vulnerability from the patch set.

Guidance for operators who delay upgrading

The notice also included advice for node operators who do not want to update until source code is available. In that case, operators are advised to restart their nodes with the --offline flag.

That mode prevents the node from making or accepting peer connections while still keeping onchain enforcement active. The project presented that option as a way to reduce exposure while preserving defenses against counterparties that might otherwise attempt to cheat on channel-related obligations.

Security caution without evidence of active attacks

Although the release is being handled under embargo, the notice explicitly said there is no known evidence that the vulnerability is currently being exploited in the wild. That leaves some uncertainty around immediate risk, but the release process indicates the issue is considered serious enough to justify temporary restrictions on source disclosure.

The short lead time is also notable. Rather than waiting for a standard release window, the project signaled that the security update should arrive roughly a day after the warning, giving operators limited time to prepare their deployment plans.

Broader maintenance and infrastructure updates

The same Bitcoin Optech newsletter also highlighted several other ecosystem developments. Ava Chow said the Hardware Wallet Interface project will move to maintenance-only work and later be archived after completing MuSig2 support and what is expected to be a final release. Chow pointed to BHWI, a Rust implementation in progress at Wizardsardine, as a possible successor.

Separately, an RFC on Delving Bitcoin proposed block-range filters as a way to cut compact block filter download sizes. In simulations on roughly 30,000 blocks, the author said a 256-block range appeared to offer the best trade-off, reducing total download size by about 70% to 80% for the tested script sets.

What comes next

The next confirmed step is the publication of Core Lightning v26.06.7 binaries, which Decker said should happen within about 24 hours. Source code is expected to follow 14 days later, at which point users who waited for disclosure should be able to verify the binaries against the released source.

Until then, the project’s own guidance draws a clear distinction between operators willing to trust the embargoed binary release and those preferring to wait and run in offline mode. Beyond that, the newsletter did not provide technical details of the vulnerability or any additional mitigation steps.

Source: bitcoinops.org