Bitcoin rallies as dovish Fed comments slash October rate hike odds
Bitcoin broke out of its range after dovish Fed comments lowered October rate hike probabilities to 25%.
Core Lightning warns of active attacks on unpatched nodes (v26.06.7 or earlier), urging upgrades. Direct risk applies mainly to node operators; wallet users…
Core Lightning, a prominent software client for Bitcoin's Lightning Network, has issued a warning that attackers are actively targeting nodes running version 26.06.7 or earlier. Funds stored in these unpatched payment channels could be exposed to theft.
The Lightning Network functions as a layer-2 payment solution, a secondary framework built atop Bitcoin. Users rely on it for quick, inexpensive transactions that occur off the main blockchain.
Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.
— Core Lightning ⚡️ (@Core_LN) October 2, 2026
We’ve received reports that attackers are targeting unpatched nodes. Keeping your node up to date is an important step in protecting your funds. https://t.co/E9ggGJsIit
The patch has been available since Sept. 22, with the release of version 26.06.8. However, the team has not disclosed which vulnerability is being exploited. They are also withholding certain technical specifics for now, to make it more difficult for others to replicate the attacks.
The changelog details several bugs that could result in financial losses for node operators. A node represents the computer running Lightning software, which holds the Bitcoin locked within payment channels.
In the most severe scenario, a faulty channel closure could transfer a node's funds to the counterparty. Other bugs allow attackers to crash nodes, taking them offline.
For the majority of Layer-2 Lightning users, the danger is more indirect. Only those who operate their own Core Lightning node need to apply the update personally.
Most individuals using Lightning via a wallet application do not run a node. In such cases, the app provider typically manages the upgrade.
Custodial wallets hold Bitcoin on behalf of their users. If a provider's node suffers losses, the provider bears the initial impact. Whether it compensates users depends on its own policies, as Lightning does not have deposit insurance.
Users of self-custodial wallets, which allow them to hold their own keys, maintain control over their channel balances. Nevertheless, a crashed provider node could temporarily disrupt their payments.
The Core Lightning warning comes at the end of a difficult period for Lightning security. In August, developers confirmed genuine Lightning vulnerabilities following a surge of AI-generated bug reports.
Earlier that month, attackers siphoned funds through a BTCPay Server flaw that exposed Lightning credentials. BTCPay Server is an open-source Bitcoin payment processor.
Lightning nodes keep keys online to route payments in real time. Consequently, outdated software provides attackers with a direct route to the funds held on those nodes.
This time, reports of attacks emerged roughly 10 days after the patch was deployed. If AI tools continue to accelerate bug discovery, that window may narrow further, leaving Core Lightning operators who postpone upgrades exposed to risk.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
Bitcoin broke out of its range after dovish Fed comments lowered October rate hike probabilities to 25%.
Citi raised its 12-month Bitcoin price target to $113,000 from $82,000 and Ethereum to $3,028, citing improved ETF flows and technical conditions.
Echo Base has launched EBRx, a restructuring and crisis advisory line for digital asset companies.
An article outlines essential features for digital asset management platforms, using 001k.bot as an example of integrated workflows.