Core Lightning Sounds Alarm: Update Immediately Due to Targeting of Outdated Nodes
The Core Lightning team has sounded an alarm for Bitcoin nodes running outdated versions of their software. Operators are urged to update immediately as attackers target unpatched nodes.
Version 26.06.7 and all earlier releases of the open-source implementation of the Bitcoin Lightning Network are affected, according to the development team. The warning follows a six-week stretch of intense security activity for the project.
The recent security update, version 26.06.8, addressed ordinary bug fixes as well as patches for flaws reported through responsible disclosure channels. The release notes credited the Bitcoin Red Team and several named researchers and organizations for their contributions.
One flaw allowed requests to exhaust memory through Core Lightning's REST interface, creating denial-of-service conditions. Another bug could crash a sender's node under certain conditions, while a channel-closing issue triggered the network's penalty mechanism, causing users to forfeit funds when attempting to settle payment channels.