Core Lightning old version vulnerability: the remote broadcast revoked the previous state; it should have triggered forfeiture (taking the breaching party’s funds). But before the fix, it might be treated as a cooperative close, bypassing forfeiture. The condition is that when opening the channel, no shutdown script was specified; this does not work for every channel. The materials say this may be able to bypass (not that the coin theft is confirmed). It’s recommended to upgrade to v26.06.8. For those who pulled the v26.06.7 Docker image during 8/28–9/1, even if startup shows a newer version, it may not include the fix—you should verify the digest.