Core Lightning Security Vulnerability: What Node Operators Must Do Now
Core Lightning has reported several confirmed security vulnerabilities and shipped an emergency update as version 26.06.7. If you run your own Lightning node, update now or restart it with the --offline switch.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you run your own Lightning node on the Core Lightning software, exactly one task is due today: the update to version 26.06.7. Blockstream says it shipped this release on August 28, 2026. It closes several confirmed security vulnerabilities, and every older release has counted as unsupported since then. If you cannot update straight away, restart the node with the --offline switch instead. Either takes a few minutes, and either is more effective than the reaction most people reach for first: switching the machine off.
If you hold Bitcoin on an exchange, in an ordinary wallet or in an app without running a node yourself, the warning does not concern you directly. What is meant is the machine that manages your payment channels. Anyone who runs none has nothing to update. It is still worth a look: the episode shows how quickly a reported programming error turns into a deadline with a date, and it is repeating itself at short intervals right now.
What happened: Core Lightning confirms vulnerabilities and ships an emergency update
Core Lightning, CLN for short, is one of several software implementations of the Lightning network. The Lightning network is a second layer above the Bitcoin blockchain: two parties jointly lock an amount in a transaction and then settle between themselves as often as they like, without writing each payment into the blockchain individually. That locked connection is called a payment channel. The software that manages such a channel, monitors it and defends it in a dispute is called a node.
In late August the CLN team reported publicly that it had spent weeks working through an unusually high number of vulnerability reports generated with the help of AI tools. Several of them turned out to be genuine. The project's instruction on its own channel was terse and ran counter to first instinct: on no account shut the node down, restart it with --offline instead, because that switch blocks connections to other nodes and thereby closes the attack path.
Accounts of the exact sequence diverge, and that is worth mentioning, because the assessment of how long the holes stood open hangs on it. The trade outlet CryptoSlate dates the arrival of the first AI-generated reports to August 13 and an initial announcement by the project to August 23. Other reports, among them the one by TFTC, put the public warning at August 26 and speak of roughly ten days of lead time. The end of that chain is documented and undisputed: on August 28 the repaired release was available as a signed program file.
No losses have been reported so far
According to the state of reporting at the time of disclosure, there were no confirmed losses of funds and no known case in which anyone actually exploited one of the holes. That is a snapshot rather than an all-clear: the technical core of the flaws stays under wraps until mid-September, and only after that can anyone check independently how large the window really was.
Am I affected? The answer depends on who runs your node
The warning applies to the Core Lightning software. Other implementations of the Lightning network are not named in the project's notice. For you the question can be answered along a simple line:
- You run your own node on Core Lightning, on a small home server, a rented machine or a ready-made package such as Umbrel or Start9: you are the addressee. Update or
--offline, today. - You run your own node on a different implementation: this warning does not speak to you. General update discipline remains sensible anyway, because notices of this kind are currently arriving at short intervals.
- You use a Lightning wallet on your phone whose node someone else runs: then the duty to update lies with that provider, not with you. You can recognise such offerings by the fact that you never update any software and never pay for a channel opening yourself. Which wallet takes which route is sorted out in our comparison of software wallets.
- You hold Bitcoin only on an exchange or on a hardware device without using Lightning: the episode does not touch your balance.
This distinction matters more than it sounds. Warnings of this kind are quickly shortened into reports about the entire Lightning network. The circle of addressees is narrower: it covers the operators of one particular piece of software in one particular release.
Version 26.06.7: why older releases are no longer supported
The repaired release carries the number 26.06.7. The project's note on it is short and hard: releases before 26.06.7 are no longer supported. That does not mean an older node comes to a halt, because technically it keeps running. It means no more security repairs will arrive for those builds and that a known attack path stays open once the source code is published.
Precision pays off on the date, because the figures diverge slightly: Blockstream's blog entry is dated August 28, 2026, while in the Umbrel app store the same release carries August 29. The difference comes from the route through the package sources and changes nothing about the substance. What matters is the number, not the day.
The next regular release, numbered 26.09, is still planned for the end of September according to the project. Anyone moving to 26.06.7 now will therefore have to do it again in a few weeks. That argues for setting up the update route cleanly once instead of hunting for it each time.

Verifying the signature: how to establish that the program file comes from the project
The project's instruction, translated literally, reads: verify the signatures of the program files, install, restart. That order is not decoration. A signature is a cryptographic endorsement with which the developers confirm that a file comes from them unaltered. Without that check a security update would make the ideal bait: the user expects a new file, actively looks for it and installs it with elevated privileges.
In this case the reason is unusually concrete. Because the source code is being withheld, nobody can trace what sits inside the file during the first two weeks. The signature is therefore, for the time being, the only indication of provenance. Anyone updating through a ready-made package does not download it personally and leaves that check to the package provider, which shifts the task rather than removing it.
The second check comes later
As soon as the source code is out in the open, the software can be rebuilt from it and compared with the file that has been running for two weeks. If the two match, it is retrospectively documented that the signed file contained nothing other than what the project published. Anyone can take that second step, and the project's assurance rests on precisely that.
Store Crypto Safely: Hardware Wallets ComparedWhat the --offline switch on a Lightning node actually turns off
The --offline switch is a start-up option of the node software. The project describes its effect as follows: it removes the attack path by taking away any means for attackers to address the node at all, while the program keeps running and keeps reading the blockchain in order to detect attempted fraud.
In practice that means the node accepts no more connections from outside and opens none itself. You can neither send nor receive payments, and other people's routed payments no longer pass through you. Everything happening on the blockchain, by contrast, your node still sees, and it can react to it.
The price is therefore stated plainly: the availability of your channels ends for as long as the switch is set. For a private node that is an inconvenience. For a node through which other people's payments regularly run, it is a loss of income. CryptoSlate points out that enough delayed updates and shut-down nodes could noticeably reduce routing capacity in parts of the network.
Why switching the machine off is worse than the offline mode
Here lies the point at which well-meant advice does damage. The obvious reaction to a security warning is: turn the device off. On a Lightning node that is the worse of two options, and the reason lies in the construction of payment channels.
A payment channel is secured by the last jointly signed balance. Either side can close the channel unilaterally at any time via the blockchain, which is known as a force close. If a counterparty submits an old balance more favourable to itself in the process, that is an attempted fraud. A challenge period protects against it: within an agreed window the injured side may submit a penalty transaction and in that case receives the entire contents of the channel.
That period runs in block time rather than calendar time, and it runs regardless of whether your machine is on. A node that has been switched off does not read the blockchain, does not notice the attempted fraud and misses the deadline. That is exactly what the project means by saying a shut-down node cannot do this job. The offline mode, by contrast, leaves the program running and the chain being read and takes away only the connections.
Anyone using a watchtower has a buffer
A watchtower is a monitoring service that observes the blockchain on your behalf and submits the penalty transaction in the event of fraud while your own node sleeps. Anyone who has set up such a service is better placed during a downtime. You should not rely on it, because many private nodes run without one, and setting it up is no incidental step.
Umbrel and Start9: how the security update reaches one-click nodes
Many private nodes run on ready-made packages with an interface rather than on the command line. There you will not find --offline as a button in the dashboard; it is a start-up option of the application. The route through the app store therefore has a story of its own here, and it can be read off the Umbrel entry.
An interim release numbered 26.06.6-patch.1 appeared there first, on August 27. Its note explained that the node kept running and kept watching the Bitcoin blockchain, but for the time being could not send, receive or forward Lightning payments. The instruction attached to it was clear: leave Core Lightning running and do not remove it, the next update would appear as usual once the repair was ready.
On August 29 came 26.06.7, with the note that this was an important security update and that the node would automatically reconnect to the Lightning network afterwards. For users of such packages that means two things. The offline mode may already have arrived automatically, without anyone flipping a switch. And full functionality returns only with the second update. If you have been wondering for a few days why a payment will not go through, here is the explanation.

Source code only on September 11: what lies behind the embargo
An embargo in this context is an agreed blackout period during which the technical details of a vulnerability are not published. That is customary between reporter and vendor ahead of the repair. Here the case is different: the repair has already shipped, and the source code nevertheless stays under wraps until September 11, 2026, fourteen days after delivery.
The reasoning is practical. From a published repair the flaw it fixes can be reverse engineered. Whoever holds the source code sees which lines have changed and often knows sooner than the defender where the attack begins. TFTC's report attributes this reasoning to CLN lead developer Christian Decker: the technical details are being held back precisely in order to stop attackers from building a working exploit out of them.
Against that it can be argued that open-source software derives its very verifiability from the fact that anyone can read along. For two weeks a file is running on the nodes whose contents nobody outside the project can follow. Both sides have an argument, and both refer to the same period. The dispute can be settled only after September 11, when a comparison between the source code and the delivered file becomes possible.
The Market Situation Every MorningAI-generated vulnerability reports: the pattern behind the emergency
The trigger of this episode is as remarkable as its course. The flaws did not come out of a planned audit. They arrived as a flood of reports generated with AI tools. Part of it was waste, part of it was genuine, and telling the two apart cost the project weeks.
For software maintained by volunteers that is a new burden. Whoever receives reports has to examine every single one, because a genuine finding overlooked would be the most expensive mistake of all. At the same time the effort on the side of those producing such reports falls towards zero. The balance between attack and defence shifts noticeably as a result.
Core Lightning is no isolated case in this. TFTC places the episode in a series and names August 3 as an earlier example, when the swap service Boltz suspended its swaps citing AI-assisted attacks. Anyone following recent weeks knows the pattern from the hardware corner too: we recently described how BitBox02 closed three security vulnerabilities with firmware 9.26.5 and why, with Coldcard, the old seed should not be reused in every case after a firmware update. How quickly you install a security update has thereby moved from a fringe topic to a routine.
What the incident means for the way you store Bitcoin
An episode like this does not imply that self-custody is a mistake. What follows from it is a division that pays off independently of this case: a Lightning node is a device permanently attached to the network, accepting connections from strangers and needing keys while it operates. Such a system remains a hot system, however carefully it is maintained.
From that follows a plain split of your holdings. What belongs in the payment channel is the amount you actually need for payments. Everything beyond that belongs in storage whose keys never sit on a machine with a network connection, of the kind our comparison of hardware wallets describes. The homework that goes with it is backing up the recovery words, on which we have gathered what steel, passphrase and multisig really achieve.
The second conclusion concerns speed. Between the warning and the repaired release lay roughly two days according to the available figures. Anyone who hears nothing of the warning in that time, because they follow neither the project nor their package source, drops out of the window. A notification route that has been set up belongs to the equipment of self-run infrastructure rather than to its comforts.
Checking the Core Lightning vulnerability: what to take away
- Check your node's version today and update to 26.06.7. If that is not possible right away, restart with
--offlineand catch up on the update afterwards. If you are not sure at all which software sits behind your Lightning payment, the comparison of software wallets clears that up. - Separate hot and cold holdings cleanly. What you need for payments stays in the channel, the rest moves to storage without a permanent network connection. Which devices manage that is set out in the hardware wallet comparison.
- Put September 11 on your list. That is the day the source code is published, and only then can the file that has been running be checked and the reach of the vulnerabilities be judged. Tools for keeping holdings and events in view are collected in our overview of analytics platforms.
The solid evidence sits in the project's notice on release 26.06.7 (Blockstream, August 28, 2026) and in the Umbrel app store entry with the notes on both updates (Umbrel App Store).
(As of August 30, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Alby Hub Security Flaw: How to Check Whether Your Bitcoin Lightning Node Is Reachable From the Internet
- Updated Core Lightning via Docker? How to Check the Security Fix Is Really There
- Bitcoin Core 32.0 Arrives October 10: How to Check Whether Your Node Falls Out of Maintenance
- Securing BTCPay Server: Why Updating to 2.4.4 Alone Does Not Protect Your Lightning Node
- Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
July 10, 2026 10:30 AM

Binance Reveals Where Its EU Users Went After MiCA
Binance just revealed where most departing EU users moved their crypto after MiCA — and the answer is raising hard questions about the new rulebook.
February 25, 2021 1:15 AM

Lightning Network Can Be Paralyzed With 0.25 BTCs Spend, Research Shows
Blockchain security researchers analyze a low-cost on the Bitcoin’s Lightning Network, which can lead to it’s paralyzation.
March 12, 2020 1:12 PM

What Is A Cold Wallet? And Why Is It Important?
A cold wallet is a wallet which is completely offline and used for storing cryptocurrencies. It is also known as cold storage.
March 31, 2026 5:13 PM

Quantum Threat to Bitcoin? Google Research Sparks Urgent Crypto Security Debate
Google’s quantum breakthrough raises fears for Bitcoin security. Can crypto survive quantum attacks—or is an upgrade urgent?
March 4, 2025 9:17 PM

Bitcoin Price Prediction ahead of the Upcoming White House Crypto Summit
With the remarkable Bitcoin volatility, and after briefly surging earlier this week before dropping again. Is a Bitcoin price surge expected ahead of or after the upcoming White House Crypto Summit?
August 12, 2026 5:53 PM

Bitcoin's Quantum Problem: Why 6.7 Million Coins Could Be Frozen Forever
A third of all Bitcoin sits in addresses a future quantum computer could crack. The proposed fix would lock those coins permanently. Here is the plan.
September 26, 2026 4:11 AM

Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
Three researchers published a draft for encrypted Bitcoin transfers without a soft fork on September 24, 2026. What Shielded Bitcoin hides, what stays public and which points you can check on your own wallet today.
May 20, 2026 10:40 AM

Bitcoin Price Stabilizes Above $77,000 as Daily Chart Shows Crucial Test
Bitcoin is trading at $77,371 following an $83,000 peak rejection, testing key daily moving average support zones amid macroeconomic friction.
June 4, 2025 1:59 PM

Crypto News Today: ETF Shocks, Trump’s Bold Bitcoin Play, and Altcoin Momentum Surging
The crypto market is pulsing with energy. From Trump’s ETF push to $1B BlackRock outflows and an altcoin breakout, today’s headlines mark a momentum shift for traders and institutions alike.
September 23, 2026 4:26 PM

Paid in Bitcoin: How to Tax Crypto Income as a Self-Employed Freelancer
A fee in Bitcoin is perfectly ordinary business income, valued at the euro price on the day it reaches you. The decisive trap comes afterwards: business assets carry no one-year holding period, so every later price move stays taxable.
September 2, 2026 10:31 PM

ECX Fork of Bitcoin: When the Snapshot at Block 973,728 Really Lands
Layertwo Labs is copying Bitcoin's ledger onto a new chain and crediting every bitcoin with one ECX. Our own measurement shows the three fork stages hang on difficulty periods, and the snapshot reported for October 31 will most likely fall on November 1.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
May 1, 2026 8:29 AM

Bitcoin Ends April with 11.87% Gain as Bulls Reclaim Key Support
Bitcoin closed April 2026 with an 11.87% gain, decisively finishing above the $75,900 monthly high and signaling a major shift in macro momentum.
April 17, 2026 10:14 PM

FIBE Berlin 2026 Review: Bitcoin, AI Trading & Tokenization at Europe's Biggest FinTech Conference
FIBE Berlin 2026 brought together the future of finance — from AI-powered crypto portfolios to Bitcoin self-custody and tokenized real-world assets.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
April 6, 2025 9:27 PM

Crypto Market Crash Updates: Will Solana Crash Below $100 as Bitcoin Falls Under $80K?
The crypto market just shed over 5% in value, with Bitcoin dipping below $80K and Ethereum sliding under $1,700. Solana is now trading at $107. So will SOL crash below $100?
January 29, 2025 8:00 AM

FOMC and Crypto: How Can the First FOMC Meeting Under Trump Affect the Crypto Market?
The first FOMC meeting under President Trump is set to take place tomorrow. Discover all possible scenarios and their impact on Bitcoin and the crypto market.
October 1, 2026 7:25 AM

US core inflation falls to 3.0 percent: what investors need to know before the Fed decision on October 28
US core inflation ran at 3.0 percent in August, clearly below the expected rate. That shifts expectations for the Fed meeting on October 28 and helps decide how much room the Bitcoin price gets in the fourth quarter.
September 30, 2026 4:14 AM

Bitcoin Price Before the Core PCE at 14:30 CEST: Will the $82,735 Level Hold?
At 14:30 CEST today the Bureau of Economic Analysis publishes the core PCE deflator for August, the inflation gauge the Fed anchors its 28 October rate decision to. Bitcoin stands at $83,329, less than $600 above its daily low, and anyone holding on leverage decides this morning.
September 27, 2026 11:28 AM

Crypto Prices Today: Bitcoin Holds $84,000 After Its Best Week Since January
Bitcoin at $84,600, ETH at $2,700, NEAR up 56 percent on the week. Crypto prices today, what drove the rally, and what could move the market next.
September 17, 2026 10:40 AM

Crypto News Today: Bitcoin Holds $76,000 After Fed Hike and CLARITY Act Collapse
The CLARITY Act died in the Senate, the Fed hiked for the first time since 2023, and Zcash ripped anyway. Here is the full crypto market update.
September 13, 2026 10:19 PM

Reporting Duty for Wallet Makers: What Has Applied Since September 11, 2026
Since September 11, 2026, anyone offering a wallet commercially in the EU must report an actively exploited vulnerability within 24 hours and inform the affected users. What Article 14 of the EU Cyber Resilience Act requires, where the limit of interpretation lies, and what you should take from it for your own custody.
September 7, 2026 1:27 PM

Liquid Network: Around 4,000 Bitcoin Drained via a Peg-Out, and What L-BTC Holders Must Check Now
Around 4,000 Bitcoin drained out of the Liquid Network federation wallet on September 6, even though no key was stolen. The network is halted and redemption is blocked. Here is what you should check now as an L-BTC holder.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 2, 2026 1:47 PM

Pi Network Protocol 27 on September 15: What Our Measurement on Mainnet and Testnet Shows
The Pi mainnet is on protocol 26 on September 2, the first testnet on 27, the second still on 26. We dated all seven protocol jumps of the past five months to the exact ledger and show what node operators and holders can read from them.
More from CryptoTicker
