Core Lightning Fixes Flaw That Could Let Cheating Nodes Avoid Penalties
Security patch released for Core Lightning
Core Lightning, a software used to run nodes on the Lightning Network, has fixed a security flaw in version 26.06.7. The issue allowed a peer to broadcast an old, revoked channel state without facing the usual penalty for cheating. While the materials describe a potential method to evade penalties, no confirmed thefts have been reported yet.
The fix addresses a specific scenario in how channel closures are handled. Normally, if a user tries to cheat by broadcasting an outdated transaction, the network allows the other party to claim a penalty. However, under certain conditions, the software previously mistook this cheating attempt as a friendly, cooperative closure.
How the vulnerability worked
- The flaw occurred when a peer did not specify a shutdown script when opening a channel.
- A malicious peer could later name the output script of an old commitment in a shutdown message.
- If the outputs matched, the software treated the transaction as legitimate, bypassing the penalty path.
- This issue is specific to Core Lightning's handling of channels and does not change Bitcoin's base rules.
Recommended actions for operators
Node operators running versions older than v26.06.7 should update immediately. The project strongly recommends upgrading to v26.06.8, which includes additional security fixes. Users who rely on Docker images must verify their image digest, as some images served between August 28 and September 1 displayed the new version number but lacked the actual security patches.
The corrected digests are listed in the release notes. If an operator's image digest does not match the corrected list, they must re-pull the image to ensure they have the secure version.
Timeline of the fix
Version 26.06.7 was originally shipped on August 28. The source code for this release was made public on September 11 after an initial embargo. The fix was merged into the main development branch on September 15. Version 26.06.8 followed on September 22 with further security updates. Bitcoin Optech explained the details of the repair in a report published on September 25.