Security· ★★★· bearish·

Core Lightning warns attackers are targeting nodes on version 26.06.7 and older

  • —Nodes on Core Lightning 26.06.7 and older are at risk
  • —The patch has been public since September 22 in version 26.06.8
  • —In a worst case, a faulty channel close could hand funds to the counterparty
  • —Only self-hosted node operators must update manually; custodial wallet users are covered by their provider
Why it matters: Outdated software gives attackers direct access to funds locked in payment channels, and AI-driven bug discovery is shrinking the window between patch and exploit.
Source: BeInCrypto ES