A bug hiding inside Core Lightning could have let bad actors steal funds by broadcasting revoked channel states without triggering the penalty mechanism that is supposed to stop them.

That is not a theoretical edge case. That is the core security promise of the Lightning Network, broken.

The flaw has been patched in Core Lightning v26.06.7, but the fix only protects users who have already upgraded. Older builds and certain early Docker images remain vulnerable right now, and the Lightning Network is not a place where "I'll update later" is an acceptable strategy.

What Actually Happened

The Lightning Network operates on a simple but brutal rule: try to cheat by broadcasting an old, revoked channel state, and your counterparty can claim every single sat in the channel as a penalty. That mechanism is the economic spine of the entire system. Remove it, and Lightning's trustless design collapses into something much closer to "hope the other person is honest."

This flaw created a window where that penalty could fail to fire. A revoked state could, under the right conditions, slip through without triggering the punishment transaction. For node operators running unpatched versions, that window is still open.

Core Lightning developers moved quickly once the vulnerability was identified, shipping the fix in v26.06.7. The responsible disclosure process appears to have worked here. But the patch is only useful if it actually reaches the nodes that need it.

Who Needs to Act Right Now

If you are running a Core Lightning node, the version check is not optional. Pull up your build number. If it reads anything older than v26.06.7, you are exposed.

Docker users face an extra wrinkle. Some early Docker images did not automatically pull the patched version, meaning operators who believe they are running a current container may still be sitting on vulnerable code. Verify the image tag directly, not just the container status.

Channel operators with significant liquidity routed through Core Lightning nodes should treat this as a critical maintenance window, not a routine update.

The Bigger Picture for Lightning

This incident is a reminder that Lightning is still maturing infrastructure. The network routes real money at scale, but the node software stack carries real engineering risk. A flaw that touches penalty logic is not cosmetic, it is foundational.

The Lightning Network's security model only holds if every participant trusts that the penalty mechanism will fire reliably. Any crack in that trust, even a patched one, gives institutional and retail users alike a reason to pause before routing larger sums.

Watch: Whether this disclosure accelerates node upgrade rates across the network. Slow adoption of security patches on Lightning has historically been a quiet systemic risk that rarely makes headlines until it does.

Update your node. Check your Docker image. Do it before you scroll to the next story.