Core Lightning warns attackers are targeting unpatched Bitcoin nodes
Node operators running version 26.06.7 or earlier were told to upgrade immediately.
Core Lightning, the open-source node software for the Bitcoin Lightning Network, has warned that attackers are targeting unpatched nodes running version 26.06.7 or earlier. The team behind Core Lightning issued an urgent security update, urging operators to upgrade to the latest release as soon as possible. They did not disclose the specific vulnerabilities being targeted or the potential impact on users.
In September, Core Lightning initially investigated reports of a potential issue affecting experimental features in their software that could impact user funds. They subsequently released version 26.06.8, addressing the issue along with bug fixes and patches for vulnerabilities reported by various sources. The release notes acknowledged contributions from the Bitcoin Red Team and 12 other individuals and groups, as well as anonymous reporters.
The September 22 update included bug fixes and patches for security vulnerabilities, with some tests deliberately withheld to prevent attackers from reverse-engineering and exploiting the vulnerabilities while users upgraded. In August, Core Lightning had also prepared a coordinated fix after receiving a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports. They subsequently released version 26.06.7 to address confirmed vulnerabilities.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.