Skip to content
Core Lightning Fixes Critical Flaw in Channel Management

Core Lightning Fixes Critical Flaw in Channel Management

First seen 28 Sep 2026, 02:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 03:34 UTC
  • •A flaw in Core Lightning allowed old channel states to be broadcast without penalties.
  • •Operators must update to at least v26.06.8 to mitigate the risk.
  • •Docker users need to verify image digests to ensure they have the correct version.

Core Lightning has patched a significant flaw in its v26.06.7 release that allowed a peer to broadcast an old, revoked channel state without incurring penalties for cheating. This vulnerability could be exploited if a peer did not specify an upfront shutdown script when opening a channel, enabling them to present a revoked commitment as legitimate. The fix, detailed in Bitcoin Optech's report from September 25, 2026, checks transaction locktime and sequence encoding to prevent such exploits. Operators using versions older than v26.06.7 are urged to update to v26.06.8, which includes additional security fixes. Docker users must verify their image digests due to a previous issue where the images reported the new version but lacked the necessary fixes. The vulnerability is specific to Core Lightning's channel management and does not affect Bitcoin's base-chain rules.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-28
Core Lightning v26.06.7 released
The release included a flaw that allowed revoked channel states to be broadcast without penalties.
Cryptoslate
2026-09-11
Source code for v26.06.7 made public
The source code was initially embargoed but was published for transparency.
Cryptoslate
2026-09-15
Pull request 9509 merged
Changes to address the flaw were merged into the main development branch.
Cryptoslate
2026-09-22
Core Lightning v26.06.8 released
This version included additional security fixes beyond the original flaw.
Cryptoslate
2026-09-25
Bitcoin Optech report published
The report detailed the vulnerability and the importance of updating to newer versions.
Cryptoslate
2026-09-28
Cryptonews article published
The article reiterated the importance of the patch and the specific conditions for exploitation.
Cryptonews

More articles in this cluster (2)

Following this threat?

Track Core Lightning in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed