TLDR
- Core Lightning warned that attackers are targeting nodes still running version 26.06.7 or earlier.
- The team has not said which vulnerabilities are being exploited or if any funds have been lost.
- Version 26.06.8 was released on Sept. 22 and fixed several security bugs, including one tied to channel closures.
- The warning follows a wave of AI-generated vulnerability reports that Core Lightning developers reviewed since August.
- Other Lightning tools, including BTCPay Server and Zeus Wallet, faced separate security incidents earlier in 2026.
Core Lightning has told node operators to upgrade immediately after receiving reports that attackers are targeting systems still running version 26.06.7 or earlier. The warning was shared on Friday.
Core Lightning node runners, this is urgent, upgrade to 26.06.8 now if you haven't already. https://t.co/geh5a7hxAF
— Blockstream (@Blockstream) October 2, 2026
The team did not say which vulnerabilities attackers are going after. It also has not said whether any of the reported attacks led to lost funds.
“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said in its statement.
Core Lightning is open-source node software used to run the Bitcoin Lightning Network. The Lightning Network allows faster, cheaper Bitcoin payments by processing them off the main blockchain.
What Changed in the Latest Update
The most recent version, 26.06.8, came out on Sept. 22. It patched several bugs that were reported to the project through responsible disclosure.
One fix addressed a flaw that could crash a sender’s node. Another covered requests that could use up memory through the software’s REST interface.
A separate bug involved channel closures. Under certain conditions, a user could lose funds to a penalty when closing a channel.
Release notes credited the Bitcoin Red Team along with 12 other named researchers and groups. Anonymous reporters were also credited.
Developers chose to withhold some tests from the public release. The goal was to make it harder for attackers to study the code and figure out how to exploit the patched flaws while operators were still updating.
A Wave of AI-Generated Reports Started It All
This isn’t the first security response from Core Lightning this year. In August, the team said it was reviewing a high volume of vulnerability reports.
Many of these reports were generated using AI tools scanning the open-source code. Not all of them pointed to real problems.
Developers spent time validating each report before deciding which issues needed fixes. Several were confirmed as real vulnerabilities.
Version 26.06.7 came out on Aug. 28 to address those confirmed issues. The source code was withheld for two weeks after release, giving operators time to upgrade before the changes became public.
Operators who could not upgrade right away were given the option to run their node in offline mode. This setting disconnects the node from Lightning peers and stops payments, but keeps the software monitoring the Bitcoin blockchain.
Other parts of the Lightning ecosystem have faced their own problems this year. In August, BTCPay Server warned about an exploit affecting installations that had not updated to version 2.4.2.
That flaw exposed administrator credentials tied to Lightning wallets. Funds were drained from some affected nodes before a 10% recovery bounty was offered, capped at 3 BTC.
Around the same time, Zeus Wallet took its infrastructure offline after a cyberattack. The company said the attack was contained within hours and that no customer funds were lost or put at risk.
Bitcoin Core, the main software behind the Bitcoin network, also disclosed a vulnerability in May. That flaw could have allowed a miner to crash nodes remotely, though it had already been patched before the public disclosure.
For now, Core Lightning’s message to operators is direct. Anyone running version 26.06.7 or earlier should upgrade right away, even though the project has not revealed how the current attacks are being carried out.







