Overview
- Core Lightning issued an urgent alert on Friday saying attackers are actively targeting nodes running version 26.06.7 or earlier and instructing operators to upgrade to 26.06.8 immediately.
- Version 26.06.8, released on Sept. 22, patched multiple security flaws that could crash nodes, exhaust memory via the REST interface, and cause fund loss during channel closures.
- Developers have not disclosed which specific vulnerability is being exploited or whether any attacks have led to stolen funds, and they deliberately withheld a small set of tests and delayed some source publication to limit reverse engineering.
- As a stopgap, Core Lightning recommended that operators who cannot update right away run their nodes in offline mode, which stops Lightning payments but keeps on‑chain monitoring active.
- The alert follows months of AI-assisted vulnerability reports beginning in August and comes amid other 2026 Lightning‑ecosystem incidents such as the BTCPay Server drainage and a Zeus Wallet infrastructure attack, raising broader operational risk for node operators and payment routing services.