Core Lightning developers have urgently called on Bitcoin Lightning Network node operators to upgrade their software after confirming active attacks against unpatched versions. Developers rev
Core Lightning developers have urgently called on Bitcoin Lightning Network node operators to upgrade their software after confirming active attacks against unpatched versions. Developers revealed that attackers are currently targeting nodes running Core Lightning version 26.06.7 or earlier, exploiting vulnerabilities that put user funds and network stability at risk.
The identified flaws enable attackers to trigger various risks, such as loss of channel funds, forced node crashes, and memory exhaustion due to malicious requests. One vulnerability involves channel closure scenarios that can result in Bitcoin being lost through the network’s penalty mechanism. Other exploits allow attackers to destabilize nodes remotely or overload their memory by exploiting the REST interface.
After detecting the issues on September 16, Core Lightning, a development team focused on the Bitcoin Lightning Network protocol, released a patched version—26.06.8—on September 24. Certain diagnostic tests were deliberately withheld from public repositories to reduce the likelihood of attackers reverse-engineering the security improvements.
Bittylicious criticized the initial response to the threat, emphasizing that operators needed to realize “upgrading to version 26.06.8 was essential, not optional.”
Kevin, an operator and community member, warned that attackers are “actively hunting” unpatched nodes. He suggested that the risk is no longer hypothetical but now an immediate threat for operators who have not updated their systems.
Discussion among Lightning users shifted from the technical aspects of the patch to concerns about the potential for a broader attack campaign. Mokiry, another Lightning observer, questioned if the incident signaled deeper, recurring vulnerabilities in Lightning infrastructure.
Mini dictionary: Core Lightning is a leading implementation of the Lightning Network protocol for Bitcoin, focusing on scalability and security to facilitate fast, off-chain bitcoin payments.
Recurring Lightning Network security incidents
The Bitcoin Lightning Network has a history of security incidents affecting node operators. In August 2026, Lightning Labs addressed an ‘update_fee’ exploit in the LND client, which allowed channel initiators to manipulate fees and potentially leave victims with unrecoverable funds. The issue was fixed in LND version 0.18.3-beta.
Another notable vulnerability, the LND Onion Bomb, was revealed in 2024. Attackers could exploit malicious onion data to trigger excessive memory use, resulting in denial-of-service conditions for nodes operating with versions earlier than 0.17.0-beta. The flaw was rated with a CVSS score of 7.5 out of 10, indicating high severity.
Incident
Date
Software Affected
Impact
Patched Version
‘update_fee’ exploit
August 2026
LND
Fee manipulation, fund loss
0.18.3-beta
Onion Bomb
2024
LND < 0.17.0-beta
Denial of service, memory exhaustion
0.17.0-beta
REST interface & channel closure vulnerabilities
September 2026
Core Lightning < 26.06.8
Fund loss, memory exhaustion, crashes
26.06.8
As of May 30, 2026, the Lightning Network consisted of approximately 17,436 public nodes, 40,986 public channels, and held around 4,870.8 BTC in channel capacity. Failures at the node-software level could threaten the reliability of significant parts of Bitcoin’s payment ecosystem.
Industry response and ongoing investment
The incident may prompt businesses and investors to place greater focus on operational security, robust software maintenance, and diversifying implementation strategies as they weigh further Lightning adoption. The speed at which node operators upgrade, along with the discovery of similar vulnerabilities in other Lightning implementations, will shape the network’s short-term resilience.
Tether emphasized the rapid growth in Lightning-based payment systems, noting that Speed processed more than $1.5 billion in annual payments, serving 1.2 million users and businesses.
Despite ongoing security issues, investment in Lightning payment infrastructure remains strong. Tether, the issuer of the stablecoin USDT, led an $8 million funding round in December 2025 for Speed, a company focused on global payment settlements using Bitcoin Lightning and stablecoins. Speed currently supports merchants, platform operators, and business clients processing large-scale payments.
Analysts expect that continued adoption and new capital inflows may further strengthen the importance of security for firms building on Lightning technology.
The post Core Lightning urges urgent node upgrade after active exploit targets Bitcoin network appeared first on COINTURK NEWS.