Core Lightning developers have issued an urgent security warning after confirming that attackers are actively targeting unpatched Bitcoin Lightning Network nodes. In an October 2 advisory, th
Core Lightning developers have issued an urgent security warning after confirming that attackers are actively targeting unpatched Bitcoin Lightning Network nodes. In an October 2 advisory, the team urged operators running Core Lightning version 26.06.7 or earlier to upgrade immediately to version 26.06.8 or a newer secure release. The warning follows the discovery of vulnerabilities affecting older versions of the Lightning node software.
The flaws create several risks for node operators, including potential loss of channel funds, remote crashes, and memory exhaustion. One vulnerability involving channel closure can cause users to lose Bitcoin through the network’s penalty mechanism, while other exploits can remotely crash nodes or overwhelm their memory through malicious requests to the REST interface.
Core Lightning began investigating a serious vulnerability on September 16 and released version 26.06.8 on September 24 with security fixes. Some diagnostic tests were withheld from the public repository to make it harder for attackers to reverse-engineer the patches.
Lightning users question whether another attack is coming
The Core Lightning warning quickly changed the conversation from a routine patch to the possibility of an ongoing attack campaign. Kevin saidattackers are now “actively hunting” unpatched Bitcoin nodes, arguing that operators running older software are no longer simply exposed to a theoretical vulnerability but could be direct targets.
Bittylicious highlighted how quickly the threat appeared to move into active exploitation. They said the targeting had occurred within the previous day or two and criticized the initial release communication for not being forceful enough. In their view, operators needed to understand that upgrading to version 26.06.8 was essential rather than optional.
The reaction was not limited to the immediate patch. Mokiry questioned whether the incident could signal more problems ahead, pointing to the recurring nature of security issues affecting Lightning infrastructure.
Lightning Network has faced similar security incidents
In August 2026, Lightning Labs disclosed an LND “update_fee” breach fee-burn exploit that allowed a channel initiator to manipulate fees before a fraudulent close, potentially leaving the victim with little or no recoverable funds. The affected versions were patched in LND 0.18.3-beta.
Another example is the LND Onion Bomb, disclosed in 2024. The vulnerability allowed excessive memory allocation through malicious onion data, creating a denial-of-service condition. It affected LND versions below 0.17.0-beta and was assigned a CVSS score of 7.5/10.
What the attack could mean for Lightning’s growth
The immediate market implication is more about the reliability of infrastructure supporting Lightning-based payments. The network had about 17,436 public nodes and 40,986 public channels as of May 30, 2026, with roughly 4,870.8 BTC in public channel capacity, meaning security failures at the node-software level can affect a meaningful layer of Bitcoin’s payment infrastructure.
For investors and businesses evaluating Lightning adoption, the incident could increase attention on operational security, software maintenance, and implementation diversity. What comes next will depend on how quickly operators migrate to patched software and whether developers identify related vulnerabilities in other implementations.
At the same time, investment in Lightning-based payment infrastructure continues to grow. In December 2025, Tether led an $8 million funding round for Speed, a payments infrastructure company using the Bitcoin Lightning Network and stablecoins to provide global settlement for merchants, platforms and other businesses. Tether said Speed was already processing more than $1.5 billion in annual payment volume and serving 1.2 million users and businesses.
Enjoyed this? BookmarkDeFi Planet, explore related topics, and follow us onTwitter,LinkedIn,Facebook,Instagram,Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.
The post Core Lightning Warns of Active Attacks on Unpatched Bitcoin Nodes appeared first on DeFi Planet.