Core Lightning Security Vulnerability: What Node Operators Must Do Now

1 month ago 22

Rommie Analytics

If you run your own Lightning node on the Core Lightning software, exactly one task is due today: the update to version 26.06.7. Blockstream says it shipped this release on August 28, 2026. It closes several confirmed security vulnerabilities, and every older release has counted as unsupported since then. If you cannot update straight away, restart the node with the --offline switch instead. Either takes a few minutes, and either is more effective than the reaction most people reach for first: switching the machine off.

If you hold Bitcoin on an exchange, in an ordinary wallet or in an app without running a node yourself, the warning does not concern you directly. What is meant is the machine that manages your payment channels. Anyone who runs none has nothing to update. It is still worth a look: the episode shows how quickly a reported programming error turns into a deadline with a date, and it is repeating itself at short intervals right now.

What happened: Core Lightning confirms vulnerabilities and ships an emergency update

Core Lightning, CLN for short, is one of several software implementations of the Lightning network. T...

Read Entire Article