TREE NEWS update: Core Lightning says attackers are targeting nodes still running version 26.06.7 or earlier. The 26.06.8 patch, released September 22, fixes a channel-closing issue that could put funds at risk as well as bugs causing crashes and memory exhaustion. The project has not disclosed the name of the exploited vulnerability and has not reported any stolen funds.
Core Lightning Warns Unpatched Nodes Targeted, Urges Upgrade to 26.06.8
The notable part is the disclosure gap: a fix shipped in 26.06.8 with no CVE name and no confirmed losses, which leaves operators unable to judge exposure beyond their own version number. Because the flaw concerns channel closing, the risk sits with node runners holding funds in active channels rather than with the wider network. Whether unpatched nodes are actually drained, and whether the project names the vulnerability later, are the open questions worth tracking.
Generated by AI for reference only.
Share on WeChat
Open WeChat → Scan → then tap "…" to send to a chat or Moments.
Tap "…" in the top-right corner to send to a chat or share to Moments.