BTC $85,924.82 +3.13%
ETH $2,726.64 +1.68%
BNB $776.29 +1.59%
XRP $1.52 +2.27%
SOL $121.26 +3.06%
TRX $0.3340 -0.96%
DOGE $0.0956 +1.40%
ADA $0.2535 +2.23%
BCH $313.83 +3.03%
LINK $14.32 +0.40%
HYPE $89.65 +0.85%
AAVE $185.60 +12.30%
SUI $1.17 +2.44%
XLM $0.2221 -0.57%
ZEC $1,378.28 -2.00%
AAPL $331.12 -0.50%
AMZN $249.50 -0.08%
GOOGL $340.04 -3.34%
MSFT $516.02 +0.88%
META $728.28 +0.39%
NVDA $231.96 +0.62%
TSLA $356.29 -0.18%
SNDK $1,788.32 +0.65%
INTC $121.02 -1.05%
SPCX $149.41 -1.30%
MU $1,093.19 +1.85%
AMD $621.39 -0.39%
BTC $85,924.82 +3.13%
ETH $2,726.64 +1.68%
BNB $776.29 +1.59%
XRP $1.52 +2.27%
SOL $121.26 +3.06%
TRX $0.3340 -0.96%
DOGE $0.0956 +1.40%
ADA $0.2535 +2.23%
BCH $313.83 +3.03%
LINK $14.32 +0.40%
HYPE $89.65 +0.85%
AAVE $185.60 +12.30%
SUI $1.17 +2.44%
XLM $0.2221 -0.57%
ZEC $1,378.28 -2.00%
AAPL $331.12 -0.50%
AMZN $249.50 -0.08%
GOOGL $340.04 -3.34%
MSFT $516.02 +0.88%
META $728.28 +0.39%
NVDA $231.96 +0.62%
TSLA $356.29 -0.18%
SNDK $1,788.32 +0.65%
INTC $121.02 -1.05%
SPCX $149.41 -1.30%
MU $1,093.19 +1.85%
AMD $621.39 -0.39%
first_img

Core Lightning warns that old version nodes are under attack and urges operators to upgrade immediately

2026-10-02 12:39:05

The Core Lightning team, which develops the open-source Bitcoin Lightning Network node software, has issued an urgent alert stating that reports indicate attackers are targeting nodes that have not installed patches, urging operators still running old versions to upgrade immediately. The team stated: "Emergency security update: If you are using version 26.06.7 or earlier, please upgrade to the latest release as soon as possible."

Prior to this, Core Lightning began investigating a potential issue that could affect its experimental features and, in turn, impact user funds on September 16, and approximately six days later, version 26.06.8 was released. This update not only fixed several defects but also provided patches for security vulnerabilities reported responsibly by multiple parties, thanking the Bitcoin Red Team and 12 other individuals and organizations in the release notes, while also acknowledging anonymous reporters.

According to the changelog, this round of fixes covers a bug that could cause sender nodes to crash, requests that could exhaust REST interface memory, and a vulnerability that could result in user funds facing confiscation losses when closing payment channels. To provide operators with ample upgrade windows and prevent attackers from taking advantage of reverse engineering and exploitation, this version intentionally obscured some testing content. Additionally, in August of this year, the project initiated a collaborative fixing process after reviewing a large number of AI-generated general vulnerability disclosure reports, and two days later released version 26.06.7 to close confirmed vulnerabilities.

app_icon
ChainCatcher Building the Web3 world with innovations.