Core Lightning rolled out a security update that prevents a channel-close flaw which could let a peer broadcast a revoked state without triggering the penalty normally imposed for cheating.
The flaw and its impact
Lightning channels rely on continuously updated commitment transactions. If a participant tries to broadcast a previously revoked commitment, the counterparty can claim a penalty on the cheating funds. The vulnerability in older Core Lightning releases allowed a malicious node to disguise such a revoked commitment as a cooperative close. This was possible when the channel was opened without an upfront shutdown script; the attacker could later supply the script from the revoked commitment in a shutdown message, making the transaction appear legitimate and bypassing the penalty path. While the issue did not result in confirmed thefts, it exposed a theoretical route for total fund loss.
How the patch resolves the issue
The corrective code now inspects a transaction’s locktime and sequence fields before evaluating its outputs. By recognizing a commitment transaction early, the software can correctly route the transaction to the penalty logic rather than treating it as a mutual close. This change is confined to the Core Lightning implementation and does not alter Bitcoin’s underlying consensus rules.
Recommended actions for node operators
Operators running versions older than v26.06.7 should upgrade immediately. The project advises moving to v26.06.8, which bundles the revoked-close fix and additional security improvements. Users who deployed Core Lightning via Docker between August 28 and September 1 should also verify the image digest, as those tags reported the newer version number but omitted the actual patches. The maintainers provide corrected digests and instructions for re-pulling the images to ensure the fix is present.
Patch rollout timeline
- v26.06.7 released on August 28, containing the initial fix but later found to be missing in some Docker tags.
- Source code for v26.06.7 was embargoed until September 11.
- Pull request 9509, which introduced the revoked-close repair, merged on September 15.
- v26.06.8 followed on September 22, adding further security fixes and making the corrected source immediately available.
- Bitcoin Optech published an explanatory note on September 25, detailing the vulnerability and the remediation steps.
Why it matters
Lightning Network security hinges on the ability of honest participants to penalize cheating. A flaw that lets an attacker evade this deterrent undermines confidence in the scaling solution and could dissuade users from adopting Lightning for high-value transfers. By addressing the bug and urging operators to update their software and Docker images, Core Lightning reinforces the network’s resilience and safeguards the funds of its participants.




