Skip to content
Core Lightning Urges Immediate Upgrade Amid Targeted Attacks on Outdated Nodes

Core Lightning Urges Immediate Upgrade Amid Targeted Attacks on Outdated Nodes

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •Core Lightning warns of active targeting of nodes running outdated software versions.
  • •Operators are urged to upgrade to version 26.06.8, which addresses multiple vulnerabilities.
  • •No confirmed reports of stolen funds have been disclosed, but the situation is urgent.

Core Lightning developers issued an urgent warning on October 2, 2026, advising operators of Bitcoin Lightning Network nodes running version 26.06.7 or earlier to upgrade immediately due to active targeting by attackers. The vulnerabilities being exploited have not been disclosed, and no confirmed theft of funds has been reported. The latest version, 26.06.8, released on September 22, 2026, includes patches for various security issues, including a channel-closing flaw that could lead to financial losses. The development team has temporarily withheld certain diagnostic tests to prevent reverse engineering of the patches. This warning follows a recent uptick in vulnerability reports, many generated by AI tools, indicating a heightened security concern within the Bitcoin ecosystem.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-05
CVE-2024-52911 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
Version 26.06.8 released
Core Lightning released an update fixing several vulnerabilities, including a critical channel-closing flaw.
Finance.Biggo
2026-10-02
Urgent warning issued
Core Lightning warned operators of nodes running version 26.06.7 or earlier to upgrade immediately due to active targeting by attackers.
Forklog

More articles in this cluster (4)

Following this threat?

Track Blockstream and CVE-2024-52911 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Versions 26.06.7 and earlier of Core Lightning are affected and should be upgraded.
Is there confirmed exploitation?
Yes, Core Lightning has reported active targeting of unpatched nodes, although no funds have been confirmed stolen.
What should I do if I'm affected?
Immediately upgrade to version 26.06.8 to mitigate the risk of exploitation.