Particle.news

Attackers Target Unpatched Core Lightning Nodes, Developers Urge Immediate Upgrade

Operators are told to install the Sept. 22 security release or enable offline mode to reduce the risk of active exploitation.

Overview

  • Core Lightning issued an urgent alert on Friday saying attackers are actively targeting nodes running version 26.06.7 or earlier and instructing operators to upgrade to 26.06.8 immediately.
  • Version 26.06.8, released on Sept. 22, patched multiple security flaws that could crash nodes, exhaust memory via the REST interface, and cause fund loss during channel closures.
  • Developers have not disclosed which specific vulnerability is being exploited or whether any attacks have led to stolen funds, and they deliberately withheld a small set of tests and delayed some source publication to limit reverse engineering.
  • As a stopgap, Core Lightning recommended that operators who cannot update right away run their nodes in offline mode, which stops Lightning payments but keeps on‑chain monitoring active.
  • The alert follows months of AI-assisted vulnerability reports beginning in August and comes amid other 2026 Lightning‑ecosystem incidents such as the BTCPay Server drainage and a Zeus Wallet infrastructure attack, raising broader operational risk for node operators and payment routing services.