Core Lightning has issued an urgent security warning after receiving reports that attackers are targeting nodes running version 26.06.7 or earlier. The project is urging operators to install version 26.06.8 immediately, escalating a security update first released on September 22. According to the official Core Lightning release, the update contains multiple vulnerability fixes that maintainers consider important enough to recommend for every user, while some associated tests remain temporarily unpublished to slow reverse engineering.
The October 2 warning materially changes the security posture around the release. When version 26.06.8 first shipped, Core Lightning described the vulnerabilities as responsibly disclosed and withheld limited test material to give operators additional time to patch. The team now says it has received reports of attackers targeting unpatched nodes, although it has not disclosed which specific flaws are being targeted or confirmed that any attack has successfully stolen funds.
Core Lightning Fixes Crash and Fund-Loss Paths
The official changelog identifies multiple remotely relevant failure modes. One allowed a receiving peer to crash a sender’s node by returning a crafted error onion, while another affected Core Lightning’s REST plugin. An unauthenticated YAML request containing anchors or aliases could consume excessive memory and crash that component. Both flaws show how untrusted peer or interface inputs could create denial-of-service conditions without compromising Bitcoin itself.
A more financially sensitive issue involved channel closing after a splice. Core Lightning says a unilateral close performed after a splice had locked could broadcast a revoked commitment transaction, exposing the channel balance to Lightning’s penalty mechanism. Version 26.06.8 corrects that behavior. Unlike the crash vulnerabilities, this bug created a path where incorrect channel-state handling could directly result in lost channel funds.
The release contains many additional hardening changes, including fixes for malformed channel-opening values, excessive gossip-query CPU use, nested XML requests and several other crash conditions. Core Lightning credited the Bitcoin Red Team, independent researchers and anonymous reporters for the security findings. The breadth of the changelog means version 26.06.8 should be treated as a substantial security maintenance release rather than a patch for one isolated vulnerability.
The update follows an earlier security cycle in August, when Core Lightning warned operators about confirmed vulnerabilities uncovered amid a surge of AI-generated reports. Version 26.06.7 was subsequently released with fixes while technical details were initially embargoed. The current incident is distinct because Core Lightning is now reporting hostile targeting of nodes that have not moved beyond that previous release.
Active Targeting Raises the Upgrade Priority
Core Lightning’s September release already recommended upgrading, but the October 2 alert makes the distinction between a theoretical vulnerability and current threat activity more important. Reports that attackers are selecting unpatched nodes do not yet establish successful exploitation, financial losses or which attack technique is being used. Operators therefore have evidence of increased exposure without a complete public forensic picture.
The security boundary also matters. Core Lightning is an implementation of Bitcoin’s Lightning Network, meaning vulnerabilities in its node software do not demonstrate a compromise of Bitcoin consensus or of every Lightning implementation. A similar distinction applied when a cyberattack disrupted ZEUS Lightning infrastructure without evidence that Lightning itself had failed. The current warning applies specifically to vulnerable Core Lightning software versions and the nodes running them.
Version 26.06.8 has been publicly available for more than a week, and its source fixes are not under embargo. Only a small number of tests remain withheld to make exploitation analysis more difficult while operators update. That window is increasingly important now that maintainers say attackers are actively looking for nodes that remain exposed.
For operators, the immediate issue is therefore operational rather than speculative: verify the installed Core Lightning version and move off 26.06.7 or earlier. There are still no publicly confirmed fund losses tied to the newly reported targeting, but the combination of known crash vectors, a channel-state bug capable of financial damage and current attacker interest gives the upgrade materially greater urgency than when the patch first shipped.
