Multiple Lightning Network node implementations have disclosed critical security vulnerabilities over the past week, prompting urgent software upgrades and warnings that unpatched infrastructure is being actively targeted by attackers. The disclosures span three major software stacks and touch on active exploitation, persistent crash loops, and broken backup compatibility, raising broad concerns about node reliability and operational continuity across Bitcoin’s layer-two ecosystem.
Core Lightning developers issued an immediate upgrade notice for node operators running version 26.06.7 or earlier, according to Cointelegraph. The project warned that attackers are actively targeting unpatched nodes, making swift migration to patched releases essential for operators still on affected versions. The advisory did not detail specific attack vectors or exploitation techniques, but the explicit urgency indicates that exploitable conditions exist for nodes remaining on outdated builds, placing them at immediate risk if left unaddressed.
Separately, new disclosures have revealed that older Eclair nodes remain exposed to a restart-related flaw even though a fix originally shipped in July. CryptoSlate reported that saved unfunded channels can overwhelm unpatched Eclair nodes every time they restart, potentially trapping operators in a recurring crash loop until they apply the update. The issue centers on how persisted unfunded channel states are handled during node initialization, with older builds lacking protections against the resource exhaustion triggered by these records. Because the vulnerability activates on every restart rather than requiring external network activity, operators who delay patching risk repeated downtime and potential data inconsistency rather than a single isolated failure.
Electrum also patched a Lightning security flaw in September, CryptoSlate noted, though the remedy introduced its own compatibility constraint. While the update repairs exports, older backups for anchor channels that relied on non-deterministic Lightning keys remain incompatible with the patched software and must be replaced. This means users with legacy backups could face significant recovery challenges despite the software itself being technically secured against the original flaw. The distinction between securing the node and preserving usable backups adds an extra remediation step for long-time Electrum users who maintained historical channel snapshots for disaster recovery.
Together, the advisories from Core Lightning, Eclair, and Electrum illustrate a concentrated wave of security maintenance across the Lightning Network stack. Each implementation faces distinct technical fallout—from active exploitation campaigns against outdated Core Lightning releases to persistent crash vulnerabilities in unpatched Eclair builds and backup fragmentation in Electrum’s Lightning key management. The overlapping disclosures underscore the operational demands placed on node operators, who must not only upgrade promptly to avoid active threats but also verify whether older channel states or backup files require manual remediation to remain usable after patching.