Core Lightning Warns Users to Upgrade Amid Reports of Node Attacks
Core Lightning, the open-source node software for the Bitcoin Lightning Network, has urged users to upgrade to the latest version, 26.06.8, after reports of attacks on unpatched nodes. The project has not disclosed the specific vulnerabilities being targeted, leaving users uncertain about the potential risks to their funds.
Core Lightning began investigating the issue on September 16, after reports of a potential problem with experimental features. The project released version 26.06.8 six days later, on September 22, which addressed several issues. However, the release notes do not provide enough information for users to determine whether their node or funds have been affected.
Node operators are recommended to upgrade to version 26.06.8 or a later release, as the fixes in this version were available immediately without an embargo. However, operators running master or development builds cannot move back to the 26.06.x series, as their database schema is newer.
Core Lightning has withheld some tests to make the vulnerabilities harder to identify and exploit while operators upgrade. The project has not specified which vulnerabilities the reported attackers are targeting or what an attack could achieve.