
Core Lightning team urges operators to upgrade from version 26.06.7 or earlier after reports of attackers targeting unpatched nodes, following a September update that patched vulnerabilities including memory exhaustion and fund-loss risks.
AI-generated summary
Core Lightning is an open-source node software for the Bitcoin Lightning Network. In August, it began addressing a high volume of AI-generated CVE reports and released version 26.06.7 to fix confirmed vulnerabilities.
The team behind Core Lightning, an open-source node software for the Bitcoin Lightning Network, has urged operators running older versions to upgrade immediately after receiving reports of attackers targeting unpatched nodes.
“Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said on Friday.
Core Lightning did not specify which vulnerabilities attackers were targeting or the potential impact. Cointelegraph reached out to Core Lightning for comment.
Source: Blockstream
On Sept. 16, Core Lightning said it was investigating reports of a potential issue affecting experimental features in Core Lightning that could impact user funds. It then released version 26.06.8 around six days later.
The Sept. 22 update delivered bug fixes alongside patches for “vulnerabilities responsibly reported by a number of sources.” The release notes credit the Bitcoin Red Team and 12 other named individuals and groups, along with anonymous reporters.
Some of the fixes addressed flaws that could crash senders’ nodes, requests that could exhaust memory in its REST interface and a channel-closing bug that could cause users to lose funds to a penalty, according to the changelog.
However, the release deliberately withheld some tests to make it harder for attackers to reverse-engineer and exploit vulnerabilities while operators upgraded.
In August, Core Lightning said it was working on a coordinated fix after assessing a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports over recent weeks.
Two days later, it released 26.06.7 to address the confirmed vulnerabilities.
AI outlook — possibilities, not facts
Core Lightning will release further updates to address remaining vulnerabilities as more details emerge from ongoing investigations.
Likely · Within weeks

NEAR Intents identified the individual responsible for a $3.8 million security breach involving user funds and gave them 48 hours to return the assets under responsible disclosure, pausing services and pledging full compensation while blockchain investigator ZachXBT traced funds to KuCoin and Bitcoin.

Crypto firms and users lost nearly $2.7 billion to security incidents in 2026 through September, with North Korea-linked thefts surpassing $1 billion. CertiK recorded 658 incidents, $420.4 million in recovered assets, and September alone accounted for $766.5 million in losses driven by major breaches at Bitget and Liquid Network. The concentration of losses in a few mega-hacks highlights systemic vulnerability, while physical 'wrench attacks' increased significantly in frequency and value.

OpenAI disrupted a coordinated extraction campaign aimed at copying its AI models' internal reasoning. The company attributed a core cluster of the activity to individuals associated with Chinese startup Moonshot AI.

Meta says its Muse AI agent cannot access iMessages on Mac without explicit user permission, requiring both Full Disk Access and its internal Messages connector to be enabled, countering a journalist's report that the app synced his texts despite denied access.

MetaMask is exiting approximately 17,000 Ethereum validators after a security breach diverted transaction-fee rewards. The mass exit has caused a significant spike in Ethereum's withdrawal backlog, reaching a nine-month high of over 773,000 ETH.

Ethereum validators face a crucial configuration choice ahead of the Glamsterdam upgrade on the Sepolia testnet on Oct. 6, where they must manually override default software settings to test an aggressive 200 million gas limit.