Cryptocurrency

Core Lightning Warns of Targeted Attacks on Unprotected Nodes

10/3/2026, 04:56 PM • Ksenia Pivneva

(edited: 10/03/2026)

Core Lightning Warns of Targeted Attacks on Unprotected Nodes

The Core Lightning team has issued a warning urging operators using versions 26.06.7 and below to immediately update their software. This warning comes after incidents of attacks on nodes that have not received patches were recorded. “Urgent security update: if you are using version 26.06.7 or earlier, please update to the latest version as soon as possible,” the developers stated.

Core Lightning did not specify which vulnerabilities were at the center of the attacks, nor did it confirm whether the recorded attacks led to any loss of funds. Version 26.06.8 was released on September 22 and addressed several vulnerabilities, including bugs that could cause node crashes, memory exhaustion, or loss of funds when closing channels. Version 26.06.7 was released on August 30 and also fixed vulnerabilities identified through the analysis of a large number of reports generated using artificial intelligence. Core Lightning developers reported a high number of vulnerability reports received from AI and began working on a coordinated update. As a result, the team confirmed the presence of multiple issues and released updates over several weeks.

In version 26.06.8, released on September 22, bugs that could lead to financial risks, including the risk of user funds loss when closing a channel, were fixed. However, it has still not been disclosed which specific vulnerabilities were targeted by the attacks, leaving the question of the security of older versions open. Core Lightning recommends operators immediately update their software to the latest release, as there have been recent reports of targeted attacks on nodes that cannot be updated. Previous security updates also did not confirm that attacks resulted in actual losses, although the current warning indicates a threat to unprotected users. This situation underscores the importance of regularly updating software, as Core Lightning developers continue to work on addressing vulnerabilities and responding to new software used for code auditing. Operators who cannot immediately install the update may temporarily switch to offline mode to protect their nodes during the update.

Popular news