Operator takeaway: Core Lightning’s guidance is to update to 26.06.7. Keep the node running during the process, follow the instructions for your installation method and verify the release against the project’s official channels. Do not uninstall the node or expose credentials while seeking help.

What Core Lightning confirmed

Core Lightning said it began receiving security reports from members of the open-source Bitcoin community in early August. The project describes the issues as confirmed vulnerabilities and released signed 26.06.7 binaries on August 28.

The public announcement does not describe the attack path, severity of each issue or whether exploitation has been observed. That absence is deliberate. Core Lightning says the source code will be published on September 11, giving operators a two-week window to upgrade before the patch itself can help reveal what changed.

That makes the wording important: this is a confirmed security update, but it is not evidence that every Core Lightning node was compromised. Operators should respond to the advisory without filling the information gap with speculation.

What node operators should do now

  1. Confirm which Lightning implementation and version the node is running.
  2. Use the official update path supplied by Core Lightning or the node platform’s maintained package.
  3. Leave the node running unless the official instructions for that installation say otherwise.
  4. Back up configuration and recovery material using the method appropriate for the setup, without copying secrets into support chats or websites.
  5. After September 11, check the published source and any follow-up technical explanation.

Umbrel’s Core Lightning package also labels 26.06.7 an important security update. Operators using a managed node interface should follow that platform’s release process rather than mixing instructions written for a source installation.

Why the source code is temporarily private

Withholding an open-source patch is unusual, especially in Bitcoin software, but the stated tradeoff is straightforward. A security patch can function as a map: comparing old and new code may expose the vulnerable component before enough nodes have upgraded.

Core Lightning says operators should later rebuild from the published source and confirm that the result matches the binary they installed. That reproducibility check matters because users are being asked to run signed binaries before the corresponding source is public.

What this means for Lightning users

Core Lightning is one implementation of the Lightning Network. The advisory does not mean Bitcoin’s base layer has been compromised, and it should not be generalized to every Lightning implementation without evidence. The affected software manages channels and routes payments on top of Bitcoin; Bitcoin blocks and on-chain validation continue under the base protocol’s rules.

Readers running their own infrastructure can use our Bitcoin node setup guide to understand the distinction between a Bitcoin full node and Lightning software. Our Bitcoin blockchain data page shows base-layer activity, but it cannot determine whether an individual Lightning installation has applied this release.

What remains unknown

The useful unanswered questions are technical: which components were affected, what conditions were required, whether any node lost funds and how operators can verify exposure. Core Lightning has not yet supplied those details publicly.

Until the September 11 disclosure, the responsible line is narrow. Update through an official channel, watch for project notices and avoid treating unverified social-media explanations as the vulnerability report.

Quick answers

Which Core Lightning version contains the fixes?

Version 26.06.7. Core Lightning recommends upgrading to that release.

Was Bitcoin itself hacked?

No such claim appears in the advisory. This update concerns Core Lightning software, not Bitcoin’s base-layer consensus rules.

When will the patch source be public?

Core Lightning says it plans to publish the source code on September 11, 2026.

SOURCES & DATA · SEPTEMBER 1, 2026
Reporting checked against the project’s official security announcement and installation documentation. See our editorial standards or report a correction.