TLDR
- Core Lightning issued an urgent alert after detecting active attacks on nodes operating version 26.06.7 and older releases.
- Developers have not disclosed the specific exploits being used or confirmed whether any operators have suffered financial losses.
- The September 22 release of version 26.06.8 patched multiple security vulnerabilities, including a critical flaw related to channel closure processes.
- This security incident comes after developers spent months reviewing AI-assisted vulnerability submissions starting in August.
- Additional Lightning Network services, such as BTCPay Server and Zeus Wallet, have experienced their own security challenges throughout 2026.
In an urgent security advisory issued Friday, Core Lightning developers have called on all node operators to immediately update their software after confirming that malicious actors are actively exploiting systems running version 26.06.7 and earlier releases.
While confirming the existence of ongoing attacks, the development team has deliberately withheld details about the specific security flaws being exploited. No confirmation has been provided regarding whether the attacks have resulted in actual fund theft from affected operators.
“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said in its statement.
Core Lightning represents one of several open-source implementations designed to power nodes on the Bitcoin Lightning Network. This second-layer solution enables rapid, low-cost Bitcoin transactions by settling them off-chain before periodically syncing with the main blockchain.
Security Patches in the Current Release
Released on September 22, version 26.06.8 incorporates fixes for multiple security issues discovered through responsible disclosure channels.
Among the resolved issues was a vulnerability that could force a sender’s node to crash unexpectedly. Additional patches addressed memory exhaustion attacks targeting the software’s REST application programming interface.
Perhaps most concerning was a channel closure bug that created scenarios where users could inadvertently trigger penalty conditions, resulting in fund forfeiture when attempting to close payment channels.
The official release documentation acknowledged contributions from the Bitcoin Red Team alongside twelve other security researchers and organizations. Several anonymous contributors were also recognized for their vulnerability reports.
In an unusual security measure, the development team deliberately excluded certain test suites from the public code repository. This strategic decision aimed to prevent potential attackers from reverse-engineering the patches to identify exploitation methods while node operators transitioned to the updated version.
AI-Driven Vulnerability Discovery Sparked Review Process
The current security situation represents the latest in a series of challenges Core Lightning has navigated throughout the year. Back in August, developers announced they were processing an unusually large influx of security vulnerability submissions.
A significant portion of these submissions originated from automated AI-powered tools analyzing the publicly available source code. However, many of these machine-generated reports did not identify genuine security threats.
The development team invested considerable resources in manually verifying each submission to distinguish legitimate vulnerabilities from false positives. This review process ultimately confirmed several authentic security flaws requiring remediation.
The August 28 release of version 26.06.7 specifically targeted these validated security issues. Following standard responsible disclosure practices, developers delayed publishing the complete source code for two weeks post-release, providing operators a critical window to update before potential attackers could examine the changes.
For operators unable to immediately apply updates, the team recommended activating offline mode as a temporary protective measure. This configuration severs connections with Lightning Network peers and halts payment processing while maintaining blockchain monitoring capabilities.
The Lightning Network infrastructure has encountered several security challenges beyond Core Lightning this year. BTCPay Server disclosed an exploit in August affecting installations that hadn’t upgraded to version 2.4.2.
This vulnerability compromised administrative access credentials associated with Lightning wallet integrations. Several nodes experienced fund drainage before the service implemented a recovery program offering a 10% bounty, with a maximum payout of 3 BTC.
During the same period, Zeus Wallet temporarily shuttered its backend infrastructure following a cybersecurity breach. Company representatives stated the incident was quickly contained and emphasized that user funds remained secure throughout the event.
Even Bitcoin Core, the reference implementation for the Bitcoin protocol itself, revealed a vulnerability in May. The flaw could have enabled miners to remotely crash network nodes, though developers had already deployed a fix prior to public disclosure.
The current guidance from Core Lightning developers remains straightforward and unambiguous. Any operator running version 26.06.7 or an earlier release must prioritize upgrading immediately, despite the limited information available about the specific attack vectors currently being leveraged.



