Update Now
Update to 26.06.7 now. It is a point release that fixes confirmed vulnerabilities reported to us over the past three weeks.
Why the Details Stay Closed for Two Weeks
In early August, Core Lightning started receiving security reports from the open-source Bitcoin community. Our team, including other contributors, took immediate action.
Signed binaries for 26.06.7 are available now. The source code will be published 14 days later (September 11, 2026).
A patch identifies the code it changes. Withholding the source code for two weeks allows operators to upgrade while reducing risk of exploits being fully understood.
As soon as we release the source code, you should verify that it matches the binary you’ve been running for the past two weeks. In order to do this, rebuild from the source code and confirm that the result matches the binary you installed.
What to Do Now
Upgrade to 26.06.7. Verify the signatures on the binaries, install, and restart.
If you cannot upgrade yet, restart with the --offline flag. Not to be confused with powering off your node, restarting with --offline eliminates the attack vector by cutting off bad actors from being able to message your node, while keeping the daemon running so you can digest the chain to detect cheating. Remove the --offline flag and restart once you have upgraded.
Releases before 26.06.7 are unsupported. The 26.09 release remains on schedule for late September.
Thank You
We’re immensely grateful for the community following responsible disclosure process:
- The reports which came in from erickcestari, project-loupe, instagibbs, benthecarman, 0xaudron, callebtc, haoxucu, vincenzopalazzo, ksedgwic, jaonoctus, whkim0, Ahmadsm2005, labrat-guy, FrancisPouliot, the Bitcoin Red Team, and moinaiagent at coinos.io.
- The remediation work was done by nGoline, cdecker, ddustin, rustyrussell, daywalker90, Lagrang3, sangbida, Andezion, and niftynei.
Next Steps
As we continue to receive more reports, we continue to actively embrace AI-assisted review to ensure improved quality, safety, and reliability for all CLN runners in the future.
We welcome other community members to participate and stay up-to-date:
- Report issues to security@blockstream.com
- Follow @Core_LN and @Blockstream