Core Lightning Warns Node Operators to Upgrade Amid Potential Attacks
Core Lightning has issued a warning to Bitcoin node operators, urging them to upgrade their software immediately to avoid potential attacks. The team received reports that attackers are targeting nodes running version 26.06.7 or earlier. The update, version 26.06.8, was released on September 22 and fixed several security flaws, including a bug that could crash a sender's node, use up a node's memory, and cause lost funds during channel closures.
The security work began in August, when developers faced a high volume of vulnerability reports from AI models used to scan open-source code. Not all reports described real problems, but several were confirmed as genuine, and the project released version 26.06.7 to fix those issues.
Other Lightning software, including BTCPay Server and Zeus Wallet, has also faced security incidents this year. Core Lightning has not disclosed the attack method or whether any funds have been lost.