Core Lightning Patches Vulnerability Allowing Evasion of Channel Penalty
Core Lightning has released version v26.06.7 to address a security flaw that could allow a peer to broadcast a revoked channel state without triggering a penalty. The vulnerability occurred when a peer, having not specified an upfront shutdown script, could use a shutdown message to match outputs with a revoked commitment, potentially bypassing penalty mechanisms. The fix introduces checks for transaction locktime and sequence encoding to correctly identify commitments. Operators are strongly advised to update to v26.06.8 to mitigate this risk.
Summaries are written by AI from the original article. Not investment advice.