Core Lightning Warns Attackers Targeting Unpatched Nodes
The Bitcoin Lightning Network node software project, Core Lightning, has sounded the alarm about attackers targeting nodes running version 26.06.7 or earlier. This comes roughly 10 days after a security patch, version 26.06.8, was released on September 22 to fix several security problems, including a channel-closing flaw that could put funds at risk. The project hasn't identified which vulnerabilities attackers are exploiting or reported any stolen funds, but operators are being told to upgrade to the latest release as soon as possible.
The patch, version 26.06.8, was meant to address several vulnerabilities, including a denial-of-service problem and a channel-closing defect. The project strongly recommends upgrading to the latest release, especially since attackers are actively targeting unpatched nodes. Blockstream, a crypto firm, has also amplified the warning and urged operators to install version 26.06.8.
It's worth noting that the vulnerabilities fixed in version 26.06.8 were intentionally left partially concealed to prevent attackers from reverse-engineering them. However, the project hasn't confirmed whether attackers are exploiting the specific flaws addressed in the patch.
The Bitcoin Lightning Network's punishment system is designed to penalize cheaters who broadcast obsolete channel states. However, a defect in the 26.06 line could cause Core Lightning to mistake certain transactions for an ordinary cooperative close and miss the revoked commitment hiding underneath, leaving the other side with funds that should have been forfeited.
Core Lightning has advised operators to install version 26.06.8 or later, verify signatures or Docker digests, and keep experimental features disabled unless they understand the risks. The project hasn't said whether attackers have succeeded in exploiting these vulnerabilities or whether any funds have been stolen.