Core Lightning has urged node operators to upgrade to version 26.06.7 after developers identified several security vulnerabilities in the Lightning Network implementation.
The emergency release issued Aug. 28, addresses issues reported during a 10-day review that included security reports generated with the help of artificial intelligence. Developers verified several findings and released fixes, while keeping technical details private under a two-week disclosure embargo.
The update is maintained by Blockstream and is used by operators running Lightning Network nodes. Developers have not disclosed the full nature of the vulnerabilities, leaving their potential impact unclear.
Operators Face Security Deadline
The embargo gives operators time to install the fixes before researchers publish details in mid-September. Unpatched nodes could face greater risk once the vulnerabilities become public.
Related: XRPL Is Moving Toward Axelar Over Its Own Bridge; Is That Safer for $XRP?
Core Lightning recommends using signed binaries when installing version 26.06.7. Operators unable to upgrade immediately can use the –offline flag to monitor their nodes until they complete the update.
Legacy Nodes Lose Support
Versions 26.04 and older no longer receive security fixes. The latest release follows version 26.06.6, published July 22.
Earlier this year, developers fixed denial-of-service flaws affecting versions 26.04 and 26.06rc2. The latest findings add to scrutiny of Lightning Network security as automated tools make it easier to identify weaknesses in widely used software.
Related: Bitcoin’s Center of Gravity Is Shifting East: Why India Could Fall Behind