TLDR
- Core Lightning told node operators running version 26.06.7 or earlier to upgrade right away after reports of attackers targeting unpatched nodes.
- The team has not said which flaws are being used or whether any funds have been lost.
- Version 26.06.8, released Sept. 22, fixed bugs that could crash nodes, use up memory or cause lost funds during channel closures.
- Earlier fixes in August followed a wave of AI generated vulnerability reports.
- Other Lightning software, including BTCPay Server and Zeus Wallet, faced security incidents this year.
Core Lightning has warned Bitcoin Lightning Network node operators to upgrade their software right away. The team said it received reports that attackers are targeting nodes running version 26.06.7 or earlier.
“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said.
The project has not said which flaws the attackers are using. It also has not said whether any attacks have worked or caused users to lose funds.
What the Latest Patch Fixed
Version 26.06.8 came out on Sept. 22. It followed a Sept. 16 notice that developers were looking into a possible problem with experimental features that could affect user funds.
The release fixed several security flaws. One bug could crash a sender’s node. Another allowed requests through the REST interface to use up a node’s memory.
A third bug carried a direct financial risk. Under certain conditions, a user could lose funds to a penalty when closing a channel.
Release notes credited the Bitcoin Red Team, 12 named researchers and groups, and several anonymous reporters. Core Lightning said there was no embargo on the update.
Developers did keep a small number of tests private. They said this would make it harder for attackers to reverse engineer the flaws while operators updated.
AI Reports Led to Earlier Fixes
The security work began in August. Developers faced a high volume of vulnerability reports as AI models were used to scan open source code.
Not every report described a real problem. Developers reviewed the submissions and confirmed several as genuine.
Version 26.06.7 was released on Aug. 28 to fix those issues. Its source code was held back for two weeks so operators could update before attackers studied the changes.
Operators who could not upgrade at the time were told they could use an offline mode. This cut the node off from peers and stopped payments, but let it keep watching the Bitcoin blockchain for channel transactions.
At that stage, the project did not report evidence of successful attacks or lost funds.
Other Lightning software has also faced problems this year. In August, BTCPay Server warned of an active exploit affecting versions before 2.4.2. The flaw exposed LND administrator credentials, and funds were drained from some nodes.
BTCPay Server backed a 10% recovery bounty, capped at 3 bitcoin. Days earlier, Zeus Wallet took its infrastructure offline after a cyberattack but said no customer funds were lost.
Bitcoin Core also disclosed a high severity bug in May that could let a miner crash vulnerable nodes. It had already been patched in version 29.0 before it was made public.
For Core Lightning users, the current instruction is direct. Nodes running 26.06.7 or older should move to the latest release as soon as possible, while the project has yet to disclose the attack method.
The post Core Lightning Warns Bitcoin Node Operators to Upgrade After Attack Reports appeared first on Blockonomi.
