Urgent Upgrade Advisory for Core Lightning Users
Operators using versions of Core Lightning up to 26.06.7 have been urgently advised to upgrade their software due to active threats from attackers exploiting vulnerabilities in outdated nodes. This warning was issued by the Core Lightning team on Friday, emphasizing the critical nature of the update:
“If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.”
Specific details regarding the vulnerabilities being exploited were not disclosed, nor was the potential impact outlined at that time. Cointelegraph attempted to obtain further information from Core Lightning but did not receive a response.
Recent Developments and Updates
On September 16, the Core Lightning team announced they were looking into reports of potential issues linked to experimental features, which could jeopardize user funds. Just over a week later, they released version 26.06.8, on September 22, which included fixes for various bugs as well as patches for vulnerabilities that had been disclosed responsibly by multiple sources.
This latest update acknowledged contributions from the Bitcoin Red Team and twelve other named individuals and groups, as well as various anonymous informants. Among the addressed issues were:
- Problems that could crash nodes during operations
- Abusive requests causing memory depletion in the REST interface
- A bug affecting channel closures that could potentially result in users incurring penalties and losing funds
According to the update’s changelog, to enhance security, the update intentionally omitted some specific tests to prevent hackers from reverse-engineering the software while operators updated their systems.
Addressing Vulnerabilities
Earlier in August, Core Lightning had begun addressing a surge in AI-generated reports of Common Vulnerabilities and Exposures (CVE), which led to the release of version 26.06.7 aimed at resolving confirmed vulnerabilities.
Conclusion
This ongoing situation highlights the importance of timely software updates in the emerging landscape of cryptocurrency and associated technologies, as vulnerabilities can lead to significant financial risks for users.