Core Lightning fixed a channel-close flaw in v26.06.7 that could let a peer broadcast an old, revoked channel state without triggering the penalty for cheating. The issue required a specific channel setup and represented a potential penalty bypass, not a confirmed theft. The project strongly recommends v26.06.8, which includes additional security fixes.
Why it matters
A revoked Lightning commitment should allow the counterparty to claim a penalty. Before the repair, a peer that had not specified an upfront shutdown script could later name the output script from a revoked commitment in a shutdown message. If the outputs matched, Core Lightning could treat the transaction as a cooperative close instead of recognizing an old commitment.
The patch checks the transaction's locktime and sequence encoding before considering its outputs as a possible mutual close. That separates the channel-handling flaw from Bitcoin's base-chain rules. The vulnerable path did not apply to every channel because it depended on the shutdown-script condition.
Market impact
Operators running a Core Lightning build older than v26.06.7 need to upgrade, with v26.06.8 the project's recommended release. Node operators using Docker should also verify the image digest: images served under v26.06.7 and related tags from Aug. 28 to Sept. 1 could report the new version at startup while lacking the fixes.
Core Lightning shipped v26.06.7 on Aug. 28, published its initially embargoed source on Sept. 11, and merged the related changes in pull request 9509 on Sept. 15. Version v26.06.8 followed on Sept. 22 with additional security fixes. Operators should confirm both the software version and, for Docker deployments, the image digest.
Frequently asked questions
-
What flaw did Core Lightning fix?
The flaw could let a peer broadcast an old, revoked channel commitment without triggering the expected penalty path. It depended on a specific shutdown-script setup.
-
Which Core Lightning version contains the repair?
The repair shipped in v26.06.7. The project strongly recommends v26.06.8, which also includes additional security fixes.
-
Did the flaw affect Bitcoin's base layer?
No. The issue involved Core Lightning's channel-handling logic and did not change Bitcoin's base-chain rules.
-
Could every Core Lightning channel be exploited?
No. The potential bypass required a channel that lacked an upfront shutdown script and matched the other conditions described in the patch.
-
What should Docker-based node operators check?
They should verify the image digest as well as the reported version. Some images served under v26.06.7 and related tags from Aug. 28 to Sept. 1 reported the update but lacked its fixes.
CryptoSlate