Core Lightning warns attackers are targeting unpatched nodes
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Core Lightning, the open-source node software for the Bitcoin Lightning Network, has issued an urgent warning for operators running version 26.06.7 or earlier to upgrade immediately. This alert follows reports of attackers targeting unpatched nodes. The recent software update, version 26.06.8, includes patches for several vulnerabilities disclosed by multiple security researchers and groups.
Why it matters
The source highlights that the security vulnerabilities could impact user funds and node stability, with some flaws potentially causing node crashes or fund loss through penalty fees. While the article does not elaborate on broader market or policy implications, the risks to node operators and users emphasize the importance of timely software updates in maintaining network security.
Key context
Core Lightning announced in mid-September that it was investigating an issue in experimental features possibly affecting funds and subsequently released version 26.06.8 with multiple bug fixes and security patches. Some tests were intentionally withheld in the update notes to prevent attackers from quickly exploiting the vulnerabilities. In August, the team addressed a surge of AI-generated CVE reports and released version 26.06.7 to handle confirmed vulnerabilities.
Key numbers and entities
Core Lightning software, Bitcoin Lightning Network, version 26.06.7, 26.06.8, Bitcoin Red Team, 12 other named security researchers/groups, Cointelegraph, Blockstream.
What remains unclear
The source does not specify the exact nature of the targeted vulnerabilities or potential impacts attackers aim to exploit. Details on the scale or success of any attacks so far are not provided. The technical specifics withheld from the release notes to prevent exploitation are also not described.