Finst

Core Lightning Warns About Vulnerable Bitcoin Nodes

The vulnerability mainly affects node operators on the Lightning Network; Core Lightning has already released update 26.06.8 to reduce risks in payment channels.

Core Lightning Warns About Vulnerable Bitcoin Nodes

Key Takeaways

  • Core Lightning warns that attackers are targeting nodes running version 26.06.7 or older.
  • Unupdated payment channels can lose funds; update 26.06.8 has been available since September 22.
  • For wallet users without their own node, the risk usually sits with the provider, while self-custodial users remain responsible themselves.

Core Lightning has warned that attackers are targeting nodes running version 26.06.7 or older. According to the developers, funds in unupdated payment channels could therefore be at risk. The update to 26.06.8 has been available since September 22, but many users still seem not to have installed it.

What Could Go Wrong

The Lightning Network is a layer-2 payment system built on top of Bitcoin. It is used for fast, cheap payments that are settled off the main chain. A node is the computer that runs Lightning software and manages Bitcoin in payment channels.

In the changelog, Core Lightning lists several bugs that could cost node operators money. In the worst case, a faulty channel close could cause funds to disappear to the other side. Other bugs could cause a node to crash and go offline temporarily.

The developers did not say exactly which bug is being exploited. They are also keeping the technical details private for now so other attackers cannot easily copy the attack.

Who Needs to Update Right Away

For most Lightning users, the risk is less direct. If you use Lightning through a wallet app, you usually are not running your own node. In that case, the provider typically handles the update.

That makes the difference between self-management and custody important. With custodial wallets, a provider holds Bitcoin on behalf of users. If such a provider loses money on its node, the provider itself takes the first hit. Whether customers get compensated depends on the terms, because Lightning does not have deposit insurance.

Users of self-custodial wallets hold their own keys and remain the owners of their channel balance. That said, a provider node that goes down can temporarily block payments.

Why This Matters More Broadly

The warning fits into a tense period around Lightning security. In August, Core Lightning developers already warned about several vulnerabilities after AI-generated security reports exposed new bugs. That shows how quickly old software can become a target when nodes use online keys to route payments in real time.

For European crypto users, this matters because Lightning is often seen as a practical layer on top of Bitcoin for small payments. At the same time, it shows that security depends heavily on who runs the node and how quickly updates are installed.

Earlier warnings from Core Lightning also show that the software has been under pressure from new bug reports for some time. That makes fast updating especially important for node operators.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.