Bitcoin Lightning Network Urgent Upgrade ⚠️ Someone is attacking nodes that haven’t been patched, and the entire industry has already had $1.26 billion stolen in Q3 🦖

👥 一起来群里抬杠

Core Lightning—the open-source node software for the Bitcoin Lightning Network—said on Friday: If you’re still running version 26.06.7 or earlier, upgrade immediately. The team said they received reports that “attackers are targeting unpatched nodes,” but they didn’t disclose which specific vulnerability it is or how big the impact is.

Even more chilling is the timeline. On September 16, they only then discovered a potential issue that could affect users’ funds, involving an experimental feature; they waited a full 6 days, and only on September 22 released the patched 26.06.8 version. The changelog is written quite plainly: fixes include a flaw that can directly crash the sending node, requests that can exhaust memory in the REST interface, and a “channel shutdown bug that could cause users to lose coins due to penalties.” The team even intentionally hid some testing details so that attackers would find it harder to reverse-engineer an exploit.

This isn’t an isolated case. CertiK data shows that in Q3 2026, the crypto industry as a whole lost $1.26 billion to theft 💥—a jump of 53.9% from Q2’s $819 million. Security incidents rose from 219 to 247. One exchange lost $387.5 million, accounting for 31% of that quarter—by far the biggest single incident of the quarter. Liquid Network took $319 million, Tectonic $120 million, and Coldcard $112.7 million followed closely.

Just in September there were 99 incidents with losses of about $769 million; fortunately, $273 million was frozen or recovered.

My translation: The target of this wave of hacking is shifting from “exchange vaults” to “infrastructure” ⚖️. Previously everyone focused on hot wallets and private keys; now even node software, cross-chain bridges, and third-party security products are becoming attack vectors. That $387.5 million theft from one exchange—was a third-party security product vulnerability being compromised, internal credentials being stolen, and then withdrawal instructions being forged.

For node operators, don’t complain about the hassle: restart when you need to, and upgrade when you need to. For ordinary users, there’s limited you can do—but don’t keep your wallet and apps on old versions. Don’t skip updates just to save time ⚠️.

Let’s chat in the comments: Do you run your own Bitcoin node? Or do you leave everything to exchange custodians?

Click the avatar to watch the live stream—every day I’ll help you follow Bitcoin hotspots. Not just what happens in the news, but also how to understand the logic and opportunities behind it 👀🚀