Core Lightning patches flaw that could let revoked channel state escape penalty

Core Lightning patches flaw that could let revoked channel state escape penalty

Summary

Core Lightning fixed a channel-close flaw in v26.06.7 that could let a peer broadcast a revoked channel commitment without triggering the intended penalty. Exploitation required a specific setup involving channels without an upfront shutdown script; the report describes a potential vulnerability, not confirmed theft. The fix checks commitment locktime and sequence before treating matching outputs as a cooperative close. Operators should update, with v26.06.8 recommended, and verify Docker image digests because some images tagged v26.06.7 during an earlier rollout lacked the patch.