Core Lightning has issued an urgent security warning to Bitcoin Lightning Network node operators after receiving reports that attackers are targeting nodes running outdated software.
The open-source Lightning Network implementation advised operators using version 26.06.7 or earlier to upgrade to the latest release immediately.
The team has not disclosed the specific vulnerabilities reportedly being exploited or provided details about the potential consequences for affected nodes. Cointelegraph contacted Core Lightning for additional information but had not received a response at the time of publication.
Latest warning follows a series of security fixes
The warning follows several security-related updates released by Core Lightning in recent months.
On Sept. 16, the project said it was investigating a potential issue involving experimental features that could put user funds at risk. Approximately six days later, Core Lightning released version 26.06.8 with multiple bug fixes and patches for vulnerabilities reported through its responsible disclosure process.
According to the release notes, security researchers and organizations including the Bitcoin Red Team, along with 12 other named contributors and anonymous reporters, helped identify the issues.
Among the vulnerabilities addressed were flaws capable of crashing nodes used to send payments, memory-exhaustion issues affecting the REST interface and a channel-closing bug that could potentially result in users losing funds through a penalty mechanism.
Core Lightning also chose not to publish certain tests included in the update. The decision was intended to limit information that could help attackers reverse-engineer the vulnerabilities while node operators had time to apply the patches.
Core Lightning has faced a broader wave of reports
The latest warning follows another security-related episode in August, when Core Lightning said it was coordinating a response after receiving a large number of AI-generated Common Vulnerabilities and Exposures (CVE) reports.
The project subsequently identified confirmed vulnerabilities and released version 26.06.7 two days later to address them.
With reports now indicating that attackers are actively targeting unpatched nodes, Core Lightning is again urging operators to move to the latest version rather than continue running older releases.