Key Highlights:
- Core Lightning v26.06.9 resolves a critical message-budget regression in v26.06.8 that inadvertently throttled peers and delayed payment channel traffic on busy nodes.
- The update mitigates fund-loss risks during channel shutdowns by automatically force-closing channels when an active Hash Time Locked Contract (HTLC) reaches its expiration deadline.
- Security enhancements patch rune authorization bypasses, mask sensitive Bitcoin RPC credentials in
listconfigs, and block configuration injection vectors viasetconfig.
Core Lightning v26.06.9 Addresses Traffic Throttling and Fund Loss Risks
Maintainers of the Core Lightning implementation have officially rolled out version 26.06.9, resolving notable regressions and security vulnerabilities that impacted Bitcoin Lightning Network node operators. The maintenance release addresses an issue introduced in v26.06.8, where ordinary network activity—such as routine gossip, peer pings, and onion messages—was incorrectly counted against a specific CPU budget intended exclusively for gossip queries. On heavily utilized nodes, this accounting error caused the software to throttle connected peers, triggering noticeable delays across channel traffic and payment routing operations.
With the deployment of Core Lightning v26.06.9, the dedicated CPU allocation is now strictly reserved for gossip queries. By ensuring that routine protocol messaging no longer depletes this operational threshold, the software removes the documented bottleneck that disrupted high-traffic routing nodes. Node runners operating v26.06.8 had been vulnerable to degraded payment performance under elevated load conditions, making this correction a critical fix for routing reliability.
Channel Shutdown Protections and HTLC Expiration Safeguards
Beyond network performance optimizations, v26.06.9 resolves a significant funds-protection flaw concerning Hash Time Locked Contracts (HTLCs). Under previous mechanics, when a channel began the shutdown procedure while carrying an in-flight payment contract that hit its deadline, forwarding operators faced severe exposure to lost funds if the settlement was fulfilled late. The changelog confirms that Core Lightning v26.06.9 now automatically force-closes the affected channel under these conditions, ensuring that forwarded funds remain protected whenever payment deadlines and channel shutdowns coincide.
The release also hardens internal operational security, notably surrounding “runes”—the authentication tokens used to grant and limit command execution within Core Lightning. Previous implementations allowed certain restricted runes to bypass constraints, creating unrestricted credentials or relisting blocklisted items. Version 26.06.9 enforces strict permission boundaries across the board, explicitly ensuring that restriction rules extend to the invokerune and destroyrune command aliases.
Coinbase Cryptographer Slams Drake’s ‘Bunker Mode’ Warning as ‘The Very Definition of FUD’
Configuration Hardening and Upgrade Considerations
Administrative and credential protections have also been enhanced in this patch. The listconfigs output now universally masks sensitive operator data, shielding recovery information and Bitcoin RPC passwords from any caller querying the node configuration. Concurrently, maintainers addressed a configuration injection vector within the setconfig command, eliminating a method through which malicious or unauthorized configuration lines could be inserted using persistent option values.
To provide node operators sufficient time to implement the updates before potential attack vectors can be easily reverse-engineered, the project maintainers have deliberately held back automated security tests from the public repository. Operators should note that instances already operating on the master development branch cannot downgrade to the 26.06.x series due to backward-incompatible database schema changes. The project development team continues to caution that dual funding remains an experimental feature, advising operators against establishing zero-confirmation channels with untrusted counterparties.
Why This Matters
Routing node operators serve as the fundamental backbone of the Lightning Network’s cross-node liquidity and payment throughput. Bugs that miscalculate peer processing limits or mismanage expiring HTLCs introduce direct systemic threats to capital safety and routing reliability. By eliminating routing slowdowns and plugging financial risks during concurrent channel closures, Core Lightning v26.06.9 prevents capital loss and performance degradation for enterprise and high-volume routing operations. Maintainers are urging all Core Lightning users, especially those running v26.06.8, to upgrade to v26.06.9 as soon as practical.
Frequently Asked Questions
Why did Core Lightning v26.06.8 experience payment delays?
In version 26.06.8, routine protocol communication such as pings, onion messages, and standard gossip messages mistakenly counted toward a specialized CPU budget designated purely for gossip queries. On high-volume nodes, this budget was quickly exhausted, causing peer throttling and routing delays.
How does v26.06.9 prevent fund loss during channel shutdowns?
When an active HTLC payment contract nears its expiration deadline at the same time a payment channel is undergoing a cooperative shutdown, v26.06.9 automatically triggers a channel force-close on-chain. This immediate closure guarantees the contract is enforced before the deadline expires, preventing loss of forwarded funds.
Can operators running the master branch downgrade to v26.06.9?
No. Nodes that have migrated to or run the master branch cannot downgrade to the 26.06.x release line because newer database schema migrations applied in master are incompatible with earlier versions.




