# Core Lightning Fixes Vulnerability That Could Evade Lightning Penalties

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/24653
Published: 2026-09-27T23:22:23.000Z
Updated: 2026-09-27T23:22:23.000Z
Section: Technology

> The flaw affected channels opened without an upfront shutdown script. Operators should verify both their software version and Docker image digest.

Core Lightning fixed a vulnerability that could let a peer broadcast a revoked Lightning channel state without triggering the network’s normal cheating penalty.

The issue affected channels opened without an upfront shutdown script. A peer could later identify the output script of a revoked commitment transaction in a shutdown message. If the transaction was classified only by its outputs, Core Lightning could treat the revoked state as a mutual close rather than a cheating attempt.

That classification could prevent the penalty transaction from being triggered. No exploitation of the flaw or resulting theft of funds has been confirmed.

The fix was included in Core Lightning v26.06.7, released Aug. 28. The related change was merged in Pull Request #9509 on Sept. 15. It checks a transaction’s locktime and sequence encoding before evaluating its outputs as possible mutual-close destinations.

Regression testing requires Core Lightning to identify the revoked commitment, sweep it with OUR_PENALTY_TX and block the peer’s delayed sweep after the CSV period. CSV, or check sequence verify, is the delay mechanism used before certain Lightning outputs can be spent.

Lightning channels use signed commitment transactions to record balances. When a channel state is revoked, broadcasting that older state is designed to trigger a penalty against the party that broadcasts it. The vulnerability involved Core Lightning’s channel-resolution logic, not Bitcoin’s base-chain consensus rules.

Operators should also verify the Docker image digest. Images served under the v26.06.7 and latest tags from Aug. 28 at 12:04 p.m. ET (16:04 UTC) through Sept. 1 reported v26.06.7 at startup but did not contain the fixes.

The corrected digest for elementsproject/lightningd:v26.06.7 and latest is sha256:0421a5f0d1b2e1ad639edfa17d777816040e3850d91bae7f2d32186d9c1e6da4.

Core Lightning released v26.06.8 on Sept. 22 at 9:38 a.m. ET (13:38 UTC) and recommends it as the project’s security release. The source code for v26.06.7 was published Sept. 11 at 7:42 a.m. ET (11:42 UTC).
