Core Lightning and MetaMask hit as attacks move down the crypto stack

- Core Lightning says attackers are targeting unpatched Bitcoin Lightning nodes running version 26.06.7 or older.
- MetaMask pulled its Lido validators offline after a security incident, with no reported customer wallet or fund losses.
- The incidents highlight growing security risks around exposed Lightning nodes and crypto infrastructure.
Core Lightning has revealed that attackers are probing unpatched Bitcoin nodes. This is coming in the same week that MetaMask spent two days pulling staking validators offline after a breach of part of its infrastructure.
Both platforms say that the incident did not touch their respective base layers. Bitcoin kept producing blocks and, according to MetaMask, no customer wallets or funds were affected.
Core Lightning tells operators to stop running old builds
Core Lightning is open-source software that many businesses and individuals use to run nodes on the Bitcoin Lightning Network. The team posted an urgent notice on October 2 telling anyone on version 26.06.7 or earlier to install the current release right away.
The project wrote on X, “We’ve received reports that attackers are targeting unpatched nodes.” It told users that moving to the current node was an important step in protecting their funds.
Core Lightning mentioned the flaws with the previous version, and it did not say anything about stolen funds.
Lightning nodes hold live balances in payment channels that sit off the main Bitcoin chain, making the alarm quite important. A reachable node that has not been patched can be messaged directly by its peers, which turns a theoretical bug into an exposed attack surface.
A compressed two months of patches
This is the latest in a series of incidents that Core Lightning has caught in the second half of 2026.
In August, the platform said that it was working through a high volume of vulnerability reports, stating that many of them were machine-generated. It then shipped version 26.06.7 on August 28.
Core Lightning held back the matching source code for roughly two weeks so operators could update before the fixes made the underlying bugs easier to reconstruct.
A second scare followed in mid-September, and maintainers had to inform operators to disable any experimental features immediately over a flaw that could put funds at risk.
Core Lightning released version 26.06.8 on September 22, this time with no embargo.
MetaMask pulls validators out of Lido
MetaMask said it was responding to a security incident affecting part of its infrastructure on September 30. Over the following day, it began exiting the Ethereum validators it operates inside Lido, the largest liquid staking protocol on Ethereum, as a precaution.
MetaMask Staking, formerly Consensys Staking, said that its operations are non-custodial and that it does not hold withdrawal keys on clients’ behalf.
In its October 1 update, the firm said it had found “no immediate threat to MetaMask wallets,” adding that there was no indication that customer funds had been accessed.
Lido, which disclosed the exits in a governance-forum notice, told stETH holders that no action was required. However, it warned the move would likely mean foregone rewards and possibly downtime penalties.
The precaution comes with a cost, as the withdrawn ETH could take up to 45 days to return. The last affected validators are expected to have exited by the end of October 7.
Lido is not the only platform that validators are being exited as Linea confirmed that validators supporting its MetaMask-linked Yield Boost vault were also being exited. However, it stated that the vault’s funds and control were unaffected.
A pattern defenders have been flagging
Both events fit a trend that the industry has been warning about. In August, BTCPay Server disclosed a critical flaw that attackers had already used to drain Lightning nodes belonging to merchants. That flaw also affected hardware wallet maker Foundation, which lost its own node in that attack.
That same month, over 30 firms, including Coinbase, Block, Blockstream, and ARK Invest, signed a letter organized by the Bitcoin Policy Institute, which pointed out that open-source security researchers are working with weaker AI tools than their attackers.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
What should Core Lightning node operators do right now?
Operators running version 26.06.7 or earlier should upgrade to the latest release immediately, according to the project's October 2 notice, after it received reports that attackers are targeting unpatched nodes.
Are MetaMask user funds at risk?
MetaMask says it has found no immediate threat to wallets and no indication that customer funds were accessed, noting its staking is non-custodial and that it does not hold withdrawal keys for clients.
Why is MetaMask's staked ETH not immediately available?
The firm is exiting its Ethereum validators on Lido as a precaution; the withdrawn ETH could take up to 45 days to return, with the last validators expected to have exited by the end of October 7.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















