Skip to content

Invest1 publisher2 min readPublished

Core Lightning says attackers are targeting nodes on its August patch or older

Core Lightning told operators on October 2 to upgrade from version 26.06.7 or older after reports that attackers are targeting unpatched nodes. MetaMask's precautionary exit from Lido that week lost no reported funds but will likely forgo rewards on ETH that can take up to 45 days to return.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Core Lightning says attackers are targeting nodes on its August patch or older
Generated illustration

What happened

  • Core Lightning shipped 26.06.7 on August 28 after saying it was working through a high volume of vulnerability reports, many of them machine-generated.
  • In mid-September, maintainers told operators to disable any experimental features immediately over a flaw that could put funds at risk.
  • MetaMask's validator exits followed a security incident affecting part of its infrastructure, which the company said it was responding to on September 30.
  • Both platforms say their base layers were untouched by the incidents, and Bitcoin kept producing blocks.
  • Linea is also exiting the validators behind its MetaMask-linked Yield Boost vault and says the vault's funds and control are unaffected.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • decision Operators who installed 26.06.7 at the end of August and stopped there are inside the range Core Lightning says attackers are targeting, so they need to upgrade again.
  • cost stETH holders pay for MetaMask's caution. Lido told them to take no action but warned them to expect forgone rewards and possible downtime penalties.
  • constraint Running a Core Lightning node now means upgrading every few weeks, after four security releases or instructions from the project in 35 days.

Core Lightning's warning rests on reports. "We've received reports that attackers are targeting unpatched nodes," the project wrote on X, and it did not mention stolen funds [2][3]. Version 26.06.8 came 25 days after the August build, and the warning came 10 days after that [3][4]. Core Lightning held back the source code for the August release for roughly two weeks, so operators could upgrade before the bugs became easier to reconstruct. Version 26.06.8 shipped with no embargo [6][8]. In August, over 30 firms, Coinbase and Block among them, signed a Bitcoin Policy Institute letter saying open-source security researchers work with weaker AI tools than their attackers [17].

Lightning's design makes a patch notice a custody matter. Nodes hold live balances in payment channels off the main Bitcoin chain, and a reachable node can be messaged directly by its peers [4]. An unpatched bug on such a node sits next to spendable money [4]. In August, attackers used a BTCPay Server flaw to drain merchants' Lightning nodes, one of them belonging to hardware wallet maker Foundation [16].

MetaMask's breach hit a different design. MetaMask Staking says it holds no withdrawal keys on clients' behalf, and the company's October 1 update said it had found "no immediate threat to MetaMask wallets" [10][11]. It exited anyway. That choice means about a week of validator exits and up to 45 days before the ETH comes back, with no rewards earned in the meantime. MetaMask took that over running validators on infrastructure where it had just disclosed an incident [6][13][12]. The report does not give the amount of ETH involved, so the cost cannot yet be sized.

There are a few ways this could go from here. Core Lightning's reports may stay reports, with no confirmed losses. Losses may surface on nodes still running 26.06.7. Or MetaMask's incident may turn out to reach beyond the part of its infrastructure the company has described [9]. I think the exposure sits with Lightning operators, who keep spendable balances on online machines, and much less with stETH holders, whose loss on this evidence is forgone yield. The counter-case is that MetaMask's no-loss account rests on its own statement about key separation [10]. A report of funds taken from a node on the current release, or a disclosure that the MetaMask incident reached client withdrawal keys, would prove that view wrong.

What to watch

  • Whether Core Lightning or any operator confirms funds taken from nodes, and on which version.
  • MetaMask's account of which part of its infrastructure was breached, and whether the last Lido exits finish by the end of October 7.
  • Lido's tally of forgone rewards and any downtime penalties once the exited ETH returns.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories