Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Core Lightning Patches Multiple Security Holes — And Keeps Some Tests Secret

Core Lightning releases a patch fixing security holes, keeping some tests secret to thwart attackers. Nodes must upgrade.

By mitch·5 min read
A glowing digital node representing a Bitcoin payment network with binary code in the background.

A new patch for Core Lightning, the program that moves money through the Bitcoin network, closes several security gaps. Some of the tests were left out of the code so that attackers cannot use them to work out how to break it.

Six days after Core Lightning said it was investigating a potential issue with experimental features that could endanger user funds, version 26.06.8 arrived. The company followed up by releasing the patch on Sept. 22, combining bug fixes and security patches for vulnerabilities reported by a group of named individuals and groups, along with anonymous reporters.

The Security Fixes In Detail

The announcement text gives credit to the Bitcoin Red Team and 12 additional named individuals and groups, alongside anonymous reporters. Among the corrections, some target issues that could cause a sender’s node to stop working, requests that could drain memory from its REST interface, and a flaw in closing channels that could leave users paying a penalty and losing funds.

Advertisement

The release left some tests out of the code on purpose. The reasoning is straightforward: the aim is to raise the bar for attackers trying to reverse-engineer and exploit vulnerabilities as operators move to newer versions. This arrangement means that a portion of the evidence supporting the fix remains hidden from public view.

How The Patch Got Here

Core Lightning announced in August that it was collaborating on a fix following an assessment of a large number of AI-generated CVE reports received over recent weeks. Two days after that announcement, it issued 26.06.7 to resolve the confirmed vulnerabilities.

The sequence follows a steady course: a caution, a trial phase, a repair, and another update since. Every stage brings the software nearer to resolving the problems, while the team keeps certain of the underlying work in reserve.

Why Withholding Tests Is A Thing

It is not unusual for security updates to withhold certain tests. When a vulnerability is being exploited by attackers, and the patch might expose information about how the system operates, the update may omit those tests entirely. The reasoning behind this approach is straightforward: giving attackers insight into how a test functions enables them to develop a working exploit more quickly than the maintainers can deploy a fix.

The company has laid its cards on the table here. Those moving up to 26.06.8 receive a fixed system, yet they are denied the complete documentation that would permit them to examine the work for themselves. This is a fair stance to take, though it does alter the trust dynamic somewhat: users must now accept the patch without being able to inspect all of its underlying construction.

What The Patch Fixes

The changelog lists three main categories of fixes:

  • Flaws that could crash a sender’s node
  • Requests that could exhaust memory in its REST interface
  • A channel-closing bug that could force users to lose funds to a penalty

There are three separate ways this system can fail, and the fix covers every one of them. The memory exhaustion problem deserves special attention because it targets the REST interface, the very channel through which outside systems communicate with Core Lightning nodes. A request that drains memory could leave a node unable to serve other requests at all.

The AI-Generated CVE Reports

The August warning pointed to a large number of AI-generated CVE reports, which marks a notable change in how security research gets done. Automated tools move much faster through codebases than people do, and they turn out huge amounts of material.

Within two days, Core Lightning had issued a coordinated fix for the confirmed vulnerabilities, releasing version 26.06.7.

What Comes Next For Users

Operators who run Core Lightning nodes have a clear course ahead: move up to version 26.06.8 and put on the patches. The firm has supplied the correction; the operator carries it out.

The outstanding issue concerns whether the patch can be confirmed to work as advertised. Without access to the withheld tests, independent reviewers lack the means to verify its claims. This is a restriction on how the update is reviewed, rather than any fault with the update itself.

Key Facts Box

  • Patch released: Version 26.06.8
  • Date of release: Sept. 22
  • Time between warning and patch: Six days
  • Credit: Bitcoin Red Team and 12 other named individuals/groups
  • Also credited: Anonymous reporters
  • Fixes include: Node crashes, memory exhaustion in REST interface, channel-closing penalty bug

Comparison Table

Feature Core Lightning 26.06.8 Earlier releases
Patch type Full bug fixes + security patches Not specified
CVE reports High volume of AI-generated Not specified
Test disclosure Withheld to protect against reverse-engineering Not specified

A change in the update process is shown in the table, with the company previously releasing fixes without holding back tests. The new method adds a protective layer, though it also takes away a layer of openness.

The Bottom Line

The Core Lightning team has pushed through a warning, a patch, and another update. They have closed the reported security gaps and kept users safe during the upgrade window by holding back certain tests.

People who operate nodes ought to move to version 26.06 point eight without delay. The update seals actual weaknesses that might put funds at risk.

The unrun tests are a concession, not a flaw. They guard the upgrade period without weakening the repair itself. The patch remains in place, and the network stays more secure because of it.

See the a run of 18 images at Cointelegraph.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.