Bitcoin Lightning Network: Unpatched Nodes Targeted in Attacks
Core Lightning has issued an urgent warning to node operators on the Bitcoin Lightning Network after receiving reports of attacks against unpatched nodes. The project advises anyone running version 26.06.7 or earlier to upgrade to the latest release as soon as possible.
The alert follows a security process that began in August, when Core Lightning disclosed multiple vulnerabilities and recommended running nodes offline if an update couldn't be made. In September, the team released version 26.06.8 with bug fixes and patches for reported issues, including crashes, REST-interface memory exhaustion, and channel-closing penalties.
Core Lightning has not identified which specific vulnerabilities attackers are currently targeting, but recommends prompt patching as a defensive action for operators. The project temporarily withheld some tests associated with the fixes to make reverse engineering more difficult and give operators time to update.