Lightning Network Teams Patch Critical Bugs Before Potential Exploitation
Three separate teams that maintain the software for Bitcoin's Lightning Network, LDK (Lightning Development Kit), Core Lightning, and Eclair, released critical security patches within a two-week period in September 2026. The patches addressed bugs that could have allowed an attacker to divert funds, crash a node, or strand channel balances. According to reports, none of the three teams have confirmed any losses associated with these vulnerabilities.
The LDK team patched two distinct problems, including a splice fee allocation flaw and a state-loading bug tied to duplicate payment hashes. The Core Lightning fix addressed a denial-of-service path that could cause a node to crash due to memory exhaustion. ACINQ's Eclair implementation received the broadest patch, fixing three separate peer-triggered vulnerabilities related to channel closures, splicing, and on-the-fly funding.
The patches were released in rapid succession: LDK v0.2.6 shipped on September 9, Core Lightning's fixes landed between September 14 and 23, and Eclair 0.14.3 was released on September 14. The timing of these disclosures raises questions about the underlying protocol's security. While the bugs were addressed before any potential exploitation, the coincidence of multiple teams finding vulnerabilities in a short period suggests that Lightning's edge cases may be more complex than previously thought.