Core Lightning Warns Node Operators to Upgrade Amid Reports of Attacks
Core Lightning has urged Bitcoin Lightning Network node operators to upgrade their software after reports of attacks on unpatched nodes. The project recommends upgrading to version 26.06.8, which was released on September 22, following an investigation into possible vulnerabilities affecting user funds.
The release notes for version 26.06.8 mention that the update addressed several issues, but the specific vulnerabilities being targeted by attackers are not disclosed. Core Lightning has also withheld a small number of tests to make it harder for operators to identify and exploit these vulnerabilities while upgrading.
Node operators running older versions, specifically 26.06.7 or earlier, should check their installed version and move to the recommended release to minimize potential risks. Those using master or development builds cannot downgrade to the 26.06.x series due to database schema changes.