FinanceFeedsCrypto

Core Lightning Urges Immediate Upgrade as Attackers Target…

By Abdelaziz Fathi

AI summary of the source article

Core Lightning has warned Bitcoin Lightning Network node operators running version 26.06.7 or earlier to upgrade immediately to version 26.06.8 after receiving reports of active targeting by attackers. The project has not disclosed the specific vulnerabilities being targeted, the attack vectors, or whether any funds have been stolen. Version 26.06.8, released on September 22, addressed issues including node-crashing bugs, memory exhaustion via the REST interface, and channel-closing flaws that could trigger fund losses. This marks the second vulnerability remediation cycle in weeks, highlighting operational risks for routing nodes, exchanges, and payment providers managing production Lightning infrastructure.

Why it matters

Core Lightning manages payment channels and holds committed bitcoin, meaning software vulnerabilities create direct operational and financial risks for businesses and node operators across the Lightning Network.

Key facts

  • Core Lightning urged operators running version 26.06.7 or earlier to immediately upgrade to version 26.06.8 due to active attacker targeting.
  • The project has not disclosed the targeted vulnerabilities, how the attacks operate, or confirmed any theft of funds.
  • Version 26.06.8 patched vulnerabilities including sender node crashes, memory exhaustion, and a channel-closing penalty flaw.