Overview
- Core Lightning issued an urgent alert on Friday saying attackers are actively targeting nodes still running version 26.06.7 or earlier and telling operators to upgrade to 26.06.8 immediately.
- Version 26.06.8, released Sept. 22, fixed bugs that could crash a sender’s node, exhaust memory through the REST interface, and trigger a channel-closure condition that can lead to fund loss.
- Developers have not disclosed which specific flaw is being exploited or whether any attacks have succeeded against operators, and they continue to withhold a small set of test artifacts to slow attacker analysis.
- Operators who cannot patch right away are advised to run Core Lightning in offline mode to stop payments while keeping blockchain monitoring active so channels can still be watched for threats.
- The alert follows months of AI-driven vulnerability reports that prompted quick patching since August and comes after other 2026 incidents such as the BTCPay Server exploit and a May Bitcoin Core fix, highlighting rising operational risk across the Lightning ecosystem.