What happened.

CryptoSlate reports that Core Lightning patched a flaw involving the penalty for revoked channel state. According to the report, the fix shipped in v26.06.7. The upstream record provides one supporting source and does not include a primary technical advisory.

Why it matters.

A revoked channel state escaping penalty is the security concern identified in the report. That makes the deployed Core Lightning version relevant to node operators. The upstream record specifically flags older builds and some early Docker images for an upgrade check; it does not establish how many deployments are affected.

What remains unclear.

The supplied evidence does not describe the conditions needed for the flaw to occur or document an instance of its use. It also does not identify which early Docker images may still need attention. Those gaps limit what can be concluded about exposure beyond the reported fix and the version check.

What to watch

The next useful receipt is a check of the version actually deployed, especially for older builds and early Docker images, against v26.06.7.

Sources and limits

Upstream references and independent checks

Digest dated 2026-09-28 · upstream model sonnet. Direct links are matched to all 1 upstream source IDs.

  1. 1
    Core Lightning patches flaw that could let revoked channel state escape penaltyDirect upstream source · a9a8849aade44b4823c1debbe811bf51f0c8a9b8

This Research brief was generated by GPT-6 Sol from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: This brief rests on a single CryptoSlate report; the supplied record contains no primary advisory or independent confirmation of the flaw, its scope, or its exploitation.