Core Lightning, one of the main software clients for Bitcoin’s Lightning Network, warned that attackers are targeting nodes running version 26.06.7 or earlier. Funds held in those unpatched payment channels could be at risk.
The Lightning Network is a layer-2 payment system, a second layer built on top of Bitcoin. Users turn to it for fast, low-cost payments that settle outside the main blockchain.
What Does Core Lightning 26.06.8 Fix?
The fix has been public since Sept. 22, when the team shipped version 26.06.8. However, the developers have not said which flaw attackers are exploiting. They are also holding back some technical details for now, making it harder for other attackers to copy the exploits.
The changelog lists several bugs that could cost node operators money. A node is the computer that runs Lightning software and holds the Bitcoin locked in payment channels.
In the worst case, a faulty channel close could hand a node’s funds to the other side. Other bugs let attackers crash nodes and knock them offline.
For most Layer-2 Lightning users, however, the risk is less direct. Only people who run their own Core Lightning node need to install the update themselves.
Most people who use Lightning through a wallet app do not run a node. In that case, the app provider usually handles the upgrade.
Custodial wallets hold Bitcoin on behalf of their users. If such a provider’s node loses funds, the provider takes the first hit. Whether it repays users depends on its own terms, since Lightning has no deposit insurance.
Users of self-custodial wallets, which let them hold their own keys, keep control of their channel balance. Still, a crashed provider node could temporarily block their payments.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
Why Are Lightning Nodes Becoming an Easier Target?
The Core Lightning warning caps a rough stretch for Lightning security. In August, developers confirmed real Lightning flaws after a flood of AI-generated bug reports.
Earlier that month, attackers stole funds through a BTCPay Server vulnerability that exposed Lightning credentials. BTCPay Server is an open-source Bitcoin payment processor.
Lightning nodes keep keys online to route payments in real time. As a result, outdated software gives attackers a direct path to the funds on those nodes.
This time, reports of attacks surfaced about 10 days after the patch shipped. If AI tools keep speeding up bug discovery, that window could shrink further, and Core Lightning operators who delay upgrades will carry the risk.


