Core Lightning's development team issued an urgent security alert on October 1, 2026, urging operators of its Bitcoin Lightning Network implementation to update their software without delay. The warning followed confirmed reports of active attacks targeting infrastructure running version 26.06.7 or earlier, a flaw that could expose bitcoin held in routing channels.
The alert was communicated through the project's official channel on X, where developers pointed node operators to version 26.06.8 as the fix. Unlike many security disclosures in the software industry, the update was released without an embargo period, meaning the patch and details of the exploit became available at the same time.
For European operators running Lightning infrastructure, the message leaves little room for delay. Core Lightning is widely used by routing node operators, exchanges and service providers across the continent that rely on the Lightning Network for faster, cheaper bitcoin settlement. An unpatched node exposed to the described attack vector risks losing funds locked in payment channels, a scenario that would directly affect liquidity providers operating in the European market.
Vulnerabilities flagged by independent researchers
According to the development team, the patch addresses multiple vulnerabilities reported responsibly by independent researchers and cybersecurity entities. Chief among them is Bitcoin Red Team, the group credited with identifying the flaws that led to this release. Bitcoin Red Team says it found the issues mid-year and has previously flagged more than 8,000 vulnerabilities across Bitcoin-related projects.
In a notable departure from typical disclosure practice, Core Lightning developers said they retained a small set of tests associated with the vulnerable code temporarily, giving operators additional time to apply the update before attackers could reverse-engineer the underlying flaws from the published fix.
Practical guidance for operators
Alongside the update instructions, the team reiterated existing operational cautions. The dual funding feature remains experimental and should be treated accordingly. Developers also advised against opening zero-confirmation channels with untrusted peers, a practice that increases exposure to exactly the kind of attack now being observed in the wild.
One technical constraint is likely to complicate remediation for some operators: nodes running master, or development, versions of the software cannot downgrade to previous 26.06.x releases. Core Lightning attributed this to a structural change in the database schema, meaning operators on development branches face a one-way upgrade path rather than the option of rolling back while they assess the patch.
For now, the project's guidance to the wider Lightning community is unambiguous: operators still running 26.06.7 or earlier should treat the update to 26.06.8 as immediate, given that the exploit is not theoretical but already active against live infrastructure.




