Core Lightning Warns of Attacks on Unpatched Bitcoin Nodes
The developers behind Core Lightning, an open-source node software that powers many Bitcoin Lightning Network setups, have issued a warning about attackers targeting unpatched nodes. In a security notice shared on Friday, the project urged operators to upgrade as soon as possible, specifically highlighting versions 26.06.7 and earlier.
The team did not provide details about the vulnerabilities being exploited or the potential impact of the attacks. However, it emphasized that the situation requires immediate attention due to active exploitation attempts against unpatched deployments.
This warning follows a sequence of identified issues affecting stability and fund safety in September updates, which included multiple vulnerability fixes and a withholding of certain tests to slow down exploitation. The project is currently responding to a surge in AI-generated CVE reports, and the current advisory suggests that the security process continued beyond earlier patches.