Core Lightning warns attackers are targeting unpatched Bitcoin nodes
Core Lightning has warned operators to upgrade immediately if they are running version 26.06.7 or earlier, citing reports that attackers are targeting unpatched nodes. The team did not disclose which flaws are being exploited or the possible impact, but earlier said it was investigating a potential issue in experimental features that could affect user funds. It later released version 26.06.8 with bug fixes and security patches for vulnerabilities reported by multiple sources. The fixes included issues that could crash sending nodes, exhaust memory through the REST interface, and a channel-closing bug that could lead to fund loss via penalty. Some test details were intentionally withheld to make exploitation harder while users update. Core Lightning had also recently addressed multiple vulnerabilities after reviewing a large number of AI-generated CVE reports.
