Key facts
- Core Lightning has warned node operators to upgrade from version 26.06.7 or earlier immediately.
- Attackers are reportedly targeting unpatched Bitcoin nodes running older versions of Core Lightning software.
- A September 22 update (version 26.06.8) included fixes for vulnerabilities that could lead to fund loss or node crashes.
- The release notes credit the Bitcoin Red Team and other sources for reporting flaws.
- Some tests were deliberately withheld from the September 22 update to hinder attackers during the upgrade period.
The team behind Core Lightning, an open-source node software for the Bitcoin Lightning Network, has issued an urgent security update, warning operators to upgrade from version 26.06.7 or earlier due to active attacks targeting unpatched nodes. The team stated on Friday that operators should upgrade to the latest release as soon as possible.