Writing · October 2026
The fix was already out.
When a tool gets recalled, the notice goes to whoever registered it. The tool cuts the same either way. Whether you hear about it depends on paperwork you filled out on a day nothing was wrong.
On Friday, the Core Lightning team posted a warning to anyone running its software at version 26.06.7 or earlier: upgrade now, because attackers are targeting nodes that haven't. The fix had been public for ten days.
What happened
Core Lightning is one of the main implementations of Bitcoin's Lightning Network, maintained at Blockstream. Its security season started on August 28, when version 26.06.7 shipped as signed binaries with the source code held back for two weeks. The desk at blockchainai.news read those fixes line by line once the embargo lifted.
Version 26.06.8 came out on September 22. This time there was no embargo. The release notes say so: "There is no embargo period for 26.06.8. The release and the associated fixes are available immediately. However, we have temporarily withheld a small number of tests to make it more difficult for prospective attackers to identify, reverse-engineer, and exploit the underlying vulnerabilities." The stated purpose was "to give users and network participants more time to upgrade before additional technical detail becomes available." Blockstream's account repeated the call to upgrade on Stacker News two days later.
Then the warning. Per Blockonomi, the project wrote on October 2: "Urgent security update: If you're running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible," and added, "We've received reports that attackers are targeting unpatched nodes." FinanceFeeds carries the same quote and the same date. Bitcoin.com News dates the post October 1. Either way, the patch was older than a week when the alarm went out.
What the project has not said: which bugs are being used, how many nodes were hit, or whether anyone lost funds. FinanceFeeds puts it plainly: "Core Lightning has so far said only that it received reports of attackers targeting unpatched nodes." Bitcoin.com News: "The project hasn't confirmed that any attack succeeded or that funds were stolen." Nothing I read changes that, so I won't.
What the changelog says
The tests were withheld. The changelog wasn't. It lists 47 fixes under 26.06.8, and three of them describe exactly what someone on the other end of a channel would want:
- "a peer receiving a payment can no longer crash the sender's node by returning a crafted error onion." You pay someone, and the act of paying them shuts your node off.
- "an unauthenticated YAML request using anchors/aliases could exhaust memory and crash the plugin." That's the REST interface. No login needed.
- "a unilateral close after a splice locked could broadcast a revoked commitment, losing the channel funds to a penalty."
That last one is the one I'd worry about. The penalty is the rule that keeps Lightning honest: publish an old state of a channel and your counterparty is allowed to take everything in it. It's built for cheaters. This bug made your own node do what a cheater does, by accident, on a close. The money doesn't go to a hacker. It goes to the person across the channel, under rules that say it's theirs.
I don't know whether that's one of the bugs being used. Nobody outside the project does. But it has been in a public changelog since September 22, in plain English, next to 46 others.
Once the fix is public, the bug is too. Withholding the tests bought time. Time only helps the people who use it.
A Lightning node is a hot wallet
A Lightning node keeps its keys online and signs on its own, all day, without asking you. That's the design. It's the most exposed thing most bitcoiners run, and it's the thing most often left on whatever version the install came with. It got set up over a weekend, it worked, and nobody looked at it again. An unpatched node with a published changelog is a hot wallet with its weak points written down where anyone can read them. The only people who haven't are the ones who own it.
What I'd do
- Find out what you're running.
lightning-cli getinforeturns aversionfield. If it reads 26.06.7 or lower, the warning is about you. If you built from source, the number looks different, and you check your commit against the v26.06.8 tag instead. - Upgrade today. Not after the weekend. The release has been out since September 22, and the project says the attacks have already started.
- If you can't upgrade today, go dark until you can. The configuration docs describe the offline option: "Do not bind to any ports, and do not try to reconnect to any peers." It shuts the door on peers without closing your channels. Take the flag off after you upgrade, or your node stays alone.
- If a bundle runs your node, the version inside the bundle is the one that counts. The project's release date is not your upgrade date. Check the number, not the news.
- Stop learning this from a social feed. On GitHub, watch the repository and pick releases only. GitHub's docs say you can "only be notified of certain event types such as issues, pull requests, releases, security alerts, or discussions." The release notice went out the day of. The warning came ten days later.
- Keep channel balances at hot-wallet size. Whatever you'd carry in a phone wallet is what belongs in channels. The rest belongs in cold storage, where a changelog can't reach it.
The recall notice was mailed. Check whether yours got read.
Verify everything, including whether the fix that's already out is already in.
— Jon Tetreault, October 2026. The habits, tools, and checks behind this piece are what I teach in Crypto Security Mastery.