Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Bitcoin Crypto News

    Core Lightning Warns of Attacks on Unpatched Bitcoin Nodes

    56 minutes ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Core Lightning Warns Of Attacks On Unpatched Bitcoin Nodes
    Core Lightning Warns Of Attacks On Unpatched Bitcoin Nodes

    The developers behind Core Lightning, the open-source node software that powers many Bitcoin Lightning Network setups, have issued an urgent call for operators to upgrade after reports that attackers are targeting unpatched nodes. In a message shared on Friday, the project singled out older releases and urged immediate action to reduce exposure.

    In the advisory, Core Lightning warned that anyone running version 26.06.7 or earlier should upgrade to the latest release โ€œas soon as possible.โ€ The team did not publicly detail which specific weaknesses are being exploited or what the attackersโ€™ immediate impact could be. Cointelegraph previously attempted to obtain additional context from Core Lightning but no further details were provided in the materials referenced here.

    Key takeaways

    • Core Lightning says attackers are targeting nodes that have not installed the latest fixes.
    • Operators on 26.06.7 or older were told to upgrade immediately.
    • The projectโ€™s earlier September updates indicate a sequence of identified issues affecting stability and fund safety.
    • Release notes for the latest update cite multiple vulnerability fixes, while also withholding certain tests to slow exploitation.
    • Core Lightning has described ongoing work to respond to a surge in AI-generated CVE reports earlier this year.

    What Core Lightning told node operators

    Core Lightningโ€™s security notice is straightforward but time-sensitive: it targets a specific range of versions and frames the upgrade as necessary due to active exploitation attempts against unpatched deployments.

    While the project did not name the vulnerabilities in the Friday post, it made clear that the situation warrants faster-than-usual maintenance. For operators, this effectively turns what might otherwise be a routine patch cycle into an immediate risk-reduction stepโ€”especially for nodes that have not been regularly updated or that run in environments where upgrade windows are constrained.

    The project did not provide an estimated scale of the attacks, nor did it specify the technical conditions attackers require beyond the absence of fixes.

    September timeline: investigation, then patch

    The latest urgency follows an earlier phase of the same broader security cycle. On Sept. 16, Core Lightning said it was investigating reports of a potential issue involving experimental features that could affect user funds.

    Approximately six days later, the team released version 26.06.8. That update combined bug fixes with security patches for vulnerabilities that were โ€œresponsibly reported by a number of sources.โ€ The release notes credited the Bitcoin Red Team, 12 other named individuals and groups, and also acknowledged anonymous reporters.

    This sequencing matters because it shows the team moved from investigation to a public patch relatively quicklyโ€”while also signaling that the most serious risks were tied to areas that may not be exercised by every operator (experimental functionality).

    Which issues were fixed in the 26.06.8 release

    According to the changelog for the Sept. 22 update, the fixes addressed multiple classes of problems, including:

    • Flaws that could crash sendersโ€™ nodes.
    • Requests that could exhaust memory via Core Lightningโ€™s REST interface.
    • a channel-closing bug that could lead to users losing funds to a penalty.

    For lightning infrastructure operators, these categories are significant because they span both availability and loss-of-funds risk. Crashes can degrade routing and liquidity management, while memory exhaustion can create denial-of-service conditions. The channel-closing defect is particularly consequential since it relates directly to the settlement behavior during channel termination.

    The release notes also indicate that Core Lightning withheld some tests. The stated rationale was to make it harder for attackers to reverse-engineer the vulnerabilities and use the information to exploit systems before upgrades are widely applied. That approach reflects a tension common in incident response: balancing transparency for defenders with limiting attacker guidance.

    Broader security pressures: CVE volume and coordinated fixes

    Core Lightningโ€™s security work has also been shaped by a broader influx of vulnerability reporting. In August, the project said it was coordinating a fix after assessing a high volume of AI-generated CVE reports over preceding weeks.

    Two days after that update, Core Lightning released 26.06.7 to address confirmed vulnerabilities. The current advisory urging upgrades from 26.06.7 or earlier suggests the security process continued beyond that earlier patch, culminating in additional fixes and an expedited response once reports of exploitation began circulating.

    For the community, the practical takeaway is that lightning node operators should treat update schedules as risk controls rather than optional maintenanceโ€”especially when upstream projects are explicitly warning about attackers and unpatched exposure.

    What to watch next

    Operators should focus on deploying the latest Core Lightning release promptly and verify that their monitoring and backup procedures align with the kinds of failures described in the changelogโ€”node crashes, REST-facing memory exhaustion, and channel closing behavior. Beyond upgrades, the open question is whether Core Lightning will provide further technical detail about the active exploitation attempts and which node configurations are most at risk.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Trump To Host Third Exclusive Memecoin Event Amid Corruption Claims

    Trump to Host Third Exclusive Memecoin Event Amid Corruption Claims

    2 hours ago
    Sec Targets Crypto Custody Hurdle For Registered Investment Advisers

    SEC Targets Crypto Custody Hurdle for Registered Investment Advisers

    3 hours ago
    Sec Proposal Would Remove Custody Barriers For Crypto Advisers

    SEC Proposal Would Remove Custody Barriers for Crypto Advisers

    4 hours ago
    Evernorth Passes Shareholder Vote For Nasdaq Listing, Holds 473m Xrp Treasury

    Evernorth Passes Shareholder Vote for Nasdaq Listing, Holds 473M XRP Treasury

    5 hours ago
    China Warns Foreign Spies As Crypto Rules Tighten; Singapore Leads

    China Warns Foreign Spies as Crypto Rules Tighten; Singapore Leads

    6 hours ago
    Trump To Host Third โ€œexclusiveโ€ Memecoin Event As Corruption Claims Persist

    Trump to Host Third โ€œExclusiveโ€ Memecoin Event as Corruption Claims Persist

    7 hours ago

    Search Crypto News

    Featured Crypto News

    Latest News

    • Core Lightning Warns of Attacks on Unpatched Bitcoin Nodes
    • Trump to Host Third Exclusive Memecoin Event Amid Corruption Claims
    • SEC Targets Crypto Custody Hurdle for Registered Investment Advisers
    • SEC Proposal Would Remove Custody Barriers for Crypto Advisers
    • Evernorth Passes Shareholder Vote for Nasdaq Listing, Holds 473M XRP Treasury
    • China Warns Foreign Spies as Crypto Rules Tighten; Singapore Leads
    • Trump to Host Third โ€œExclusiveโ€ Memecoin Event as Corruption Claims Persist
    • Evernorth Wins Shareholder Approval for Nasdaq Debut, Holds 473M XRP Treasury
    • 50,000 Europeans urge EU to relax stablecoin reward limits in MiCA review
    • 50,000 Europeans urge EU to loosen stablecoin rewards under MiCA

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Tangem 300x300
    eToro Crypto 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Bitpanda
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!