Core Lightning maintainers issued an urgent security alert on October 2, 2026, confirming that attackers are actively targeting nodes running version 26.06.7 or earlier. The warning follows a 10-day window in which a patched release (v26.06.8, shipped September 22) closed three vulnerability clas...
"We're experiencing a massive collision between decades of human open source slop against 2 weeks of Kimi K3. Everything is broken, Bitcoin is burning." — Calle, Bitcoin Red Team Lead
Core Lightning maintainers issued an urgent security alert on October 2, 2026, confirming that attackers are actively targeting nodes running version 26.06.7 or earlier. The warning follows a 10-day window in which a patched release (v26.06.8, shipped September 22) closed three vulnerability classes — including a channel-closing flaw that can force operators to forfeit funds through Bitcoin's penalty mechanism. No confirmed losses have been disclosed. The team withheld exploit details and test suites from the public repository to slow reverse-engineering.
The incident lands amid a broader security reckoning across Bitcoin's infrastructure layer. In August 2026, a critical BTCPay Server vulnerability allowed unauthenticated attackers to steal LND macaroon credentials and drain merchant Lightning nodes. In the same month, the volunteer Bitcoin Red Team — armed with Chinese AI model Kimi K3 — scanned 501 open-source Bitcoin projects, logged 7,958 findings, and classified 1,280 as high or critical severity. Lightning applications, the team reported, carried security status "worse than average." The convergence of AI-powered vulnerability discovery, a thinning node base (down to 17,438 from a 2022 peak of 20,700), and active exploitation raises a structural question: whether Bitcoin's second-layer infrastructure can absorb the security debt its open-source codebase has accumulated.
On October 2, 2026, Core Lightning — the open-source Lightning Network implementation maintained by Blockstream — posted an urgent advisory telling node operators to upgrade immediately. The statement was terse: "If you're running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible." It disclosed no exploit paths, named no attackers, and confirmed no fund losses.
Version 26.06.8 had been available since September 22, giving operators a 10-day head start before the public warning. The release notes credited the Bitcoin Red Team, 12 named researchers and security groups, and several anonymous contributors. Certain test suites were deliberately excluded from the public repository — an unusual step intended to prevent adversaries from reverse-engineering patch differentials into working exploits.
The timeline suggests Blockstream detected active exploitation roughly 10 days after the patch shipped, indicating that attackers were monitoring public code changes and targeting operators who had not yet applied the update.
Version 26.06.8 patched three distinct bug classes:
1. Crash-on-Send Bug. An attacker could trigger a crash on the sending node under specific conditions. A crashed node cannot monitor channel state, creating a window during which counterparties may broadcast outdated commitment transactions.
2. REST Interface Memory Exhaustion. Malicious requests to Core Lightning's REST API could consume all available system memory, producing a denial-of-service condition. For operators running CLN on shared infrastructure, this flaw could cascade beyond the Lightning node itself.
3. Channel-Closing Penalty Exploit. The most consequential flaw: a bug in the channel-closing logic that could cause operators to lose funds through Bitcoin's penalty mechanism. In Lightning's design, if a party broadcasts a revoked (outdated) channel state, the counterparty can claim the entire channel balance as a penalty. This vulnerability could manipulate the closing process to trigger that penalty condition against the honest operator.
The team did not specify which of the three flaws attackers are actively exploiting. The penalty exploit carries the highest financial risk, as it can result in total loss of a channel's value.
The Lightning Network's infrastructure has contracted even as transaction volume grows. As of mid-2026:
| Metric | Value | Trend | |--------|-------|-------| | Public nodes | 17,438 | Down from 20,700 peak (2022) | | Public channels | 41,080 | Stable | | Public capacity | ~4,898 BTC | Down from 5,637 BTC all-time high (Dec. 2025) | | Estimated total capacity (incl. private) | >12,000 BTC | Difficult to verify | | Monthly transaction volume | >$1 billion | Crossed threshold Feb. 2026 | | Monthly transactions | ~12 million | Late 2025 estimate |
The node count decline — a 16% drop from peak — does not necessarily indicate weakness. Analysts at Spark Money describe it as "network restructuring: fewer nodes operating more efficiently." However, fewer nodes means each remaining node holds more capacity and routes more traffic, amplifying the impact of any single node compromise.
Core Lightning's market share is estimated at roughly 5% of public nodes, compared to LND's ~90% dominance. Eclair accounts for less than 1%. But CLN's share understates its importance: CLN nodes tend to be operated by technically sophisticated users and infrastructure providers who route disproportionate traffic relative to their count.
The Core Lightning alert did not occur in isolation. Eight weeks earlier, on August 7, 2026, BTCPay Server — the open-source self-hosted payment processor used by thousands of Bitcoin merchants — confirmed that a critical vulnerability in all versions before 2.4.2 was being actively exploited.
The flaw allowed unauthenticated, remote attackers to steal LND ".macaroon" credential files. A macaroon is LND's bearer-token API credential; anyone holding an admin macaroon controls the node outright, including the ability to open, close, and drain payment channels. On-chain wallets were not affected.
Bitcoin Red Team researchers Bruno Garcia and Ben Carman identified the vulnerability and reported it to BTCPay maintainers. A 10% recovery bounty was offered, capped at 3 BTC. The disclosure underscored a systemic issue: Bitcoin's merchant payment infrastructure shares the same codebase dependencies — and the same attack surface — as its Lightning routing layer.
Updating to v2.4.2 closed the access path but did not invalidate credentials already stolen. Operators were advised to revoke all LND macaroons and migrate funds from any BTCPay-generated hot wallet.
The August-October 2026 period marks the first time AI models were deployed at scale against Bitcoin's open-source codebase — and the results were uncomfortable.
The Bitcoin Red Team, a volunteer group led by the pseudonymous developer Calle, initially used American AI models from OpenAI and Anthropic for code review. According to Calle, these providers imposed restrictions during security research that limited the depth of analysis. The team shifted to Kimi K3, a model from Chinese AI lab Moonshot AI, and GLM 5.2 from Z.ai.
CertiK CEO Ronghui Gu framed the broader dynamic: "A protocol can pass a flawless code audit and still lose millions because of a compromised admin key." While CertiK's observation targets DeFi — where compromised keys drove 70% of the $1.3 billion in first-half 2026 losses — the principle applies equally to Lightning infrastructure, where credential theft (BTCPay macaroons) and node-level vulnerabilities (CLN bugs) represent the same "human layer" attack surface.
The 2026 OSSRA report from Black Duck found that the mean number of open-source vulnerabilities per codebase has risen 107% to 581 vulnerabilities, a trend the report correlates with AI-accelerated development that outpaces security review.
Two sweeps by the Bitcoin Red Team produced the following:
First sweep (reported August 13-14, 2026):
Second sweep (reported September 2026):
Kimi K3 scored 32% on the ExploitBench security benchmark and achieved arbitrary code execution on 0 of 41 test samples, according to the U.K. AI Security Institute and U.S. CAISI assessment. Despite these modest benchmark numbers, the model's ability to surface real, exploitable vulnerabilities at scale — including the BTCPay credential theft — demonstrated that AI-assisted auditing has crossed a threshold where it produces actionable results against production Bitcoin software.
OpenSats, the non-profit funding Bitcoin and open-source development, established a fast-tracked grant route for red-teaming in response to the findings.
LND's ~90% share of public Lightning nodes creates a monoculture risk that security researchers have flagged repeatedly. A single implementation-specific vulnerability in LND would affect the vast majority of network capacity.
Core Lightning's October 2 alert affects a smaller node base, but the incident illustrates a pattern: Lightning implementations are maintained by small teams (Blockstream for CLN, Lightning Labs for LND, ACINQ for Eclair) whose security review cadence may not match the rate at which AI tools and adversaries now discover flaws.
The Zeus Wallet backend infrastructure attack in August 2026 — which reportedly did not result in fund losses — adds a third vector: mobile wallet infrastructure. Lightning's security perimeter extends from node software to payment processors to mobile interfaces, each maintained by separate teams with varying resources.
The CLN alert echoes a prior Lightning security event. On October 16, 2023, developer Antoine Riard published a description of "replacement cycling attacks" — a method to steal funds from HTLC (Hash Time Lock Contract) channels by exploiting mempool inconsistencies. The disclosure produced four CVEs (CVE-2023-40231 through -40234) and patches across all major implementations.
Riard subsequently stepped back from Lightning development, citing a "hard dilemma" between the need for responsible disclosure and the structural difficulty of securing a protocol whose security model depends on constant monitoring by every node operator. His concern — that Lightning's security assumptions may not scale — gains renewed relevance as the October 2026 attack demonstrates that adversaries are now actively scanning for unpatched nodes within days of a security release.
The October 2026 Core Lightning security event is not, by itself, a systemic crisis. CLN represents roughly 5% of public Lightning nodes. No fund losses have been confirmed. The patch was available 10 days before attackers arrived.
But the incident is diagnostic. It demonstrates that Bitcoin's second-layer infrastructure now operates in a security environment where AI tools surface vulnerabilities faster than maintainers can ship patches and operators can apply them. The Bitcoin Red Team's 7,958 findings — accumulated in 108 hours across 501 projects — suggest the open-source ecosystem carries a volume of security debt that manual review never uncovered.
For operators, the calculus has changed. The window between disclosure and exploitation has compressed from months to days. For the Lightning Network's maintainers — small teams at Blockstream, Lightning Labs, and ACINQ — the question is whether their security review cadence can absorb the output of AI-assisted adversaries and auditors operating at scale.
The data does not yet support a conclusion that Lightning is fundamentally insecure. Monthly volume exceeds $1 billion. The network processes an estimated 12 million transactions per month. But the infrastructure supporting that volume is thinner than it was two years ago, and the adversaries probing it are materially more capable than they were two months ago.