Skip to content
Core Lightning Warns of Attacks on Unpatched Nodes

Core Lightning Warns of Attacks on Unpatched Nodes

Forklog • October 2, 2026

On October 2, Core Lightning developers urged node operators running versions 26.06.7 and earlier to urgently update their software. The team received reports of attackers targeting nodes lacking the latest security patches.

Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible. We’ve received reports that attackers are targeting unpatched nodes. Keeping your node up to date is an important step in protecting your funds. — Core Lightning ⚡️ (@Core_LN) October 2, 2026

Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.

We’ve received reports that attackers are targeting unpatched nodes. Keeping your node up to date is an important step in protecting your funds.

— Core Lightning ⚡️ (@Core_LN) October 2, 2026

The team did not specify which vulnerabilities attackers are exploiting or the potential consequences. The announcement also did not mention any confirmed loss of funds.

Core Lightning is a popular implementation of the Bitcoin micropayment protocol Lightning Network , created and maintained by Blockstream.

The current stable version is 26.06.8, released on September 22 . Developers included bug fixes and vulnerability patches reported by Bitcoin Red Team, independent researchers, and other community members.

The team strongly recommended upgrading to this version. Some tests for the fixed issues were temporarily withheld to complicate reverse engineering of the patches and give operators more time to update.

In August, the team encountered numerous vulnerability reports, some generated by AI tools. After verification, developers confirmed the existence of real security issues.

On August 27, Core Lightning representatives recommended switching nodes to offline mode with the —offline parameter if operators were not ready to install patches immediately. This disconnects the node from Lightning peers but allows it to continue monitoring the Bitcoin blockchain.

The following day, version 26.06.7 was released with fixes for confirmed vulnerabilities. Patch details were initially hidden for two weeks to reduce the risk of reverse engineering until a significant portion of the network was updated. The source code was made public on September 11.

On September 16, Core Lightning separately warned operators with experimental features enabled to disable them during the investigation of potential issues that could affect user funds. Six days later, developers released version 26.06.8 with additional security fixes, which the team now recommends for node operators using version 26.06.7 and earlier.

In August, attackers extracted funds from Lightning Network nodes operating through the BTCPay payment server. Developers confirmed the theft and urged users of the LND program to immediately update to version 2.4.2 or disable the server.

Follow ForkLog on social media Telegram (main channel) X Found a mistake in the text? Select it and press CTRL+ENTER

Follow ForkLog on social media

Hackers Exploit BTCPay Vulnerability to Drain Lightning Nodes

BTCPay Offers Up to 3 BTC Reward for Return of Stolen Coins

Approximately 99% of Bitcoin’s Taproot Transactions Are ‘Dust’

Amboss Unveils RailsX DEX Based on Bitcoin’s Lightning Protocol

Square Tests Bitcoin Lightning Payments via POS Terminals

Engineers Propose Method for Sending Bitcoin to Mars

Wallet of Satoshi Begins Beta Testing Non-Custodial Bitcoin Wallet

BitBox Fixes Two Major Vulnerabilities in Bitcoin Wallet Firmware

‘Sleep at Night Technology’: How a Coldcard flaw turned peace of mind into a nightmare

Extracted Entities

Attack Types (1)

Companies (2)

Platforms (1)