Bitcoin Lightning Security Alert Issued as Attackers Target Older Core Lightning Nodes

BTC
security vulnerabilityAI generated reportsLightning NetworkCore Lightningnode upgradeBitcoin
12 hours agoSource: crypto.news
Bitcoin Lightning Security Alert Issued as Attackers Target Older Core Lightning Nodes

Core Lightning has warned Bitcoin Lightning Network node operators to upgrade immediately after receiving reports that attackers are targeting systems still running version 26.06.7 or earlier.

Summary

  • Core Lightning has urged operators running version 26.06.7 or earlier to upgrade immediately after receiving reports of attackers targeting unpatched nodes.
  • The team has not disclosed which vulnerabilities are being exploited or whether any of the reported attacks have resulted in lost funds.
  • Version 26.06.8 patched several security flaws, including bugs that could crash nodes, exhaust memory or cause funds to be lost during channel closures.
  • The warning follows several Core Lightning security updates since August, when developers confirmed vulnerabilities after reviewing a wave of AI generated reports.

According to the Core Lightning team, operators using affected older releases should move to the latest version as soon as possible, weeks after developers released another round of security fixes for the open source Lightning node software.

“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said.

Core Lightning has not disclosed which vulnerabilities are being targeted in the reported attacks or what an attacker could potentially achieve against an unpatched node. The warning therefore does not establish whether the attacks involve one of the flaws fixed in September or a separate issue affecting older versions.

The alert follows a series of security updates that Core Lightning developers have released since August. As crypto.news previously reported, the project confirmed multiple vulnerabilities in August after reviewing a large number of AI generated Common Vulnerabilities and Exposures reports.

At the time, operators waiting for the security release were given the option of running Core Lightning with its offline setting. The configuration disconnected a node from Lightning peers and stopped payments from being sent, received or routed while allowing the daemon to continue monitoring the Bitcoin blockchain.

Core Lightning has already patched another set of vulnerabilities

Security work continued into September when Core Lightning said on Sept. 16 that it was investigating reports of a potential problem involving experimental features.

Developers said the issue could affect user funds, though detailed information about the problem was not immediately released. Version 26.06.8 followed on Sept. 22 with bug fixes and patches covering vulnerabilities that had been responsibly disclosed to the project.

Release notes for 26.06.8 credited the Bitcoin Red Team alongside 12 named researchers and groups, as well as people who chose to report issues anonymously.

Core Lightning strongly recommended installing the release and said there was no embargo period for the update. Developers nevertheless temporarily withheld a small number of tests from the public release.

The project said keeping the tests private would make it more difficult for prospective attackers to identify and reverse engineer the underlying vulnerabilities while operators were still updating their nodes.

Several security related fixes can be identified from the software changelog. One dealt with a problem capable of crashing a sender’s node, while another addressed requests that could consume available memory through Core Lightning’s REST interface.

A separate channel closing problem carried a direct financial risk. Under certain conditions, the bug could result in a user losing funds to a penalty when a channel was closed.

Core Lightning has not said whether any of those specific flaws are now being targeted. Its latest warning only states that reports have been received of attackers going after unpatched nodes.

Earlier Core Lightning fixes followed a wave of AI reports

The latest situation follows another coordinated security response that began in August.

Core Lightning said at the time that developers had been dealing with a high volume of vulnerability reports as increasingly capable AI models were used to examine open source code for possible security problems.

Not every submission represented a genuine vulnerability, leaving developers to review and validate the reports before deciding which issues required fixes. Several reports were eventually confirmed as legitimate problems.

Version 26.06.7 was released on Aug. 28 to address vulnerabilities identified during that work. Developers initially withheld its source code for two weeks in an effort to give operators time to update before prospective attackers could study the changes and work backwards to identify the patched flaws.

The source was published after the embargo ended in September.

During the earlier security response, Core Lightning told operators that upgrading should be their main course of action. Nodes that could not immediately install the security release could temporarily run in offline mode instead of completely stopping the daemon.

Keeping the daemon active allowed the node to continue watching Bitcoin for channel related transactions. A fully stopped Lightning node would not perform the same monitoring while offline.

The project did not disclose evidence at that stage that attackers had successfully exploited the vulnerabilities or that users had lost funds through the confirmed flaws.

The situation has now changed in one respect: Core Lightning says it has received reports that attackers are targeting nodes that have not been patched, although it has not disclosed whether any attack has succeeded or resulted in losses.

Lightning software has faced other security incidents

Other software connected to Bitcoin’s Lightning ecosystem has dealt with security problems during 2026.

In August, BTCPay Server warned users about an active Lightning exploit affecting installations that had not moved to version 2.4.2.

The flaw exposed LND administrator macaroon credentials on vulnerable BTCPay Server installations. An administrator macaroon carries extensive permissions over an associated Lightning wallet, giving attackers a path to access connected wallets after obtaining the credential.

Funds were drained from some affected Lightning nodes. BTCPay Server later backed a 10% recovery bounty, capped at 3 BTC if all stolen assets were recovered.

BTCPay said all releases before version 2.4.2 were affected, including release candidate versions of 2.4.2. Onchain wallets were not affected by the flaw.

Another incident had occurred days earlier when Zeus Wallet took infrastructure offline following a cyberattack.

Zeus said the attack was contained within hours and kept its infrastructure offline while conducting an audit. The self custodial Lightning wallet said customer funds were neither lost nor placed at risk, while its investigation had not identified a vulnerability in Lightning node software.

Users whose Lightning Service Provider channels were closed during the incident were told that replacement channels would be provided after services resumed.

Bitcoin node software has required security updates elsewhere

Security fixes have not been limited to software operating directly on Lightning.

Bitcoin Core disclosed a high severity vulnerability in May that could allow a miner to remotely crash vulnerable Bitcoin nodes. The Bitcoin Core vulnerability tracked as CVE-2024-52911, affected releases after version 0.14.0 and before version 29.0.

Developers had already patched the issue in Bitcoin Core 29.0 before publicly disclosing it.

The flaw involved Bitcoin Core’s script interpreter during block validation. A specially constructed invalid block could cause a node to attempt to access data after the relevant memory had been freed.

Triggering the vulnerability required an attacker to produce a specially crafted block carrying enough proof of work to reach the chain tip, making exploitation costly. Bitcoin Core said remote code execution was possible but considered that outcome unlikely because of restrictions on block data.

For Core Lightning operators, the immediate instruction is narrower. Nodes still running 26.06.7 or any earlier version have been told to move to the latest release as soon as possible, while the project has yet to disclose the attack method or identify which patched vulnerability is being targeted.