Core Lightning, a Lightning Network node implementation, has patched a channel-close flaw that could potentially allow a peer to broadcast an old, revoked channel state without triggering the penalty mechanism designed to punish cheating. The fix was released in version 26.06.7.
Lightning Network peers update their channel commitments as balances change. Normally, if one party broadcasts a revoked commitment, the counterparty can claim a penalty. However, the vulnerability allowed Core Lightning to misidentify a revoked commitment spend as a cooperative channel close when its outputs matched previously recorded shutdown scripts.
The flaw depended on a specific channel configuration. A peer that had not specified an upfront shutdown script when opening the channel could later provide the output script of its revoked commitment in a shutdown message, then abandon the cooperative close and broadcast the old commitment. The system would recognize it as legitimate based solely on matching outputs, bypassing the penalty mechanism.
What the Fix Does
The repair checks a transaction's locktime and sequence encoding to identify a commitment transaction before examining its outputs as a potential mutual close. According to the maintainers' patch notes and regression test, this prevents the bypass of the penalty path.
The vulnerability represents a potential method to evade penalties rather than a confirmed theft, and it is specific to Core Lightning's channel handling—not a change to Bitcoin's base-layer rules.
What Operators Need to Do
Operators running Core Lightning builds older than v26.06.7 should upgrade immediately. The project recommends v26.06.8, a later security release that includes additional fixes.
The revoked-close vulnerability requires the specific shutdown-script condition described above, meaning not every channel in a vulnerable version could be exploited this way.
Operators who deployed Docker images from the earlier rollout should verify their image digest. According to the project's release notes, Docker images tagged as v26.06.7 and related versions served between August 28 and September 1 reported the new version on startup but did not include the security fixes. The project has published corrected digests, and users with mismatched digests should re-pull the image.


