Bitcoin Thursday — October 1, 2026
by @chaosmagic23 · 2026-10-01
*Lightning security, post-quantum research, Bitcoin Core testing, and multisig backup recovery.*

Bitcoin development rarely moves in one dramatic leap. This week is a good example: an important Lightning security update deserves attention now, while other work points toward what nodes and wallets may need in the future.
## 1. Core Lightning releases a security update
Core Lightning **26.06.8**, released on September 22, fixes bugs and vulnerabilities reported responsibly by security researchers. The project strongly recommends that operators upgrade. Some tests have temporarily been withheld to give nodes more time to update before the flaws become easier to reproduce.
The release credits the **Bitcoin Red Team**, several named researchers, and anonymous reporters.
If you run Core Lightning, this is the practical item on this week’s list: check your installed version and read the operator notes before upgrading. This advisory concerns **Core Lightning**; it does not mean that every Lightning implementation has the same vulnerability.
**Source:** [Core Lightning 26.06.8 — official release notes](https://github.com/ElementsProject/lightning/releases/tag/v26.06.8)
### Bitcoin meme of the week

*Coffee can wait. The channels can’t.*
## 2. Researchers propose post-quantum protection for Lightning
**Ahmet Kurt, Abdul-Salem Beibitkhan, Yacoub Hanna, and Abdullah Aydeger** have proposed **PQLN**, a way to add post-quantum protection to Lightning’s off-chain communication.
Their design covers areas such as node gossip, peer connections, invoices, offers, and payment routing. They have also published a research implementation based on rust-lightning.
The proposal remains **research rather than an adopted network upgrade**. Its main trade-off is bandwidth: the researchers report substantially more gossip data, even though the extra cryptographic computation was small in their tests.
It also does not solve Bitcoin’s on-chain quantum questions. For node operators, this is a development to follow while researchers and developers test and debate the design.
The paper was submitted on **September 12, 2026**, and Bitcoin Optech covered the proposal in its **September 25** newsletter.
**Sources:** [PQLN — original research paper](https://arxiv.org/abs/2609.13781) · [Bitcoin Optech Newsletter #424](https://bitcoinops.org/en/newsletters/2026/09/25/)
## 3. Bitcoin Core 32.0 enters wider testing
**Bitcoin Core 32.0rc2** is available as a release candidate, and the project has asked people to test 32.0 across supported systems and alongside other software.
The published release plan aims for a final version in October, but that date remains a target.
For operators, **“release candidate” means test version**. Those who want to help can use the project’s testing guide and report reproducible problems. Others can wait for the final release and its completed notes before planning a production upgrade.
The rc2 download files are dated **September 22, 2026**, when the project’s testing issue was also opened.
**Sources:** [Official Bitcoin Core 32.0rc2 downloads](https://bitcoincore.org/bin/bitcoin-core-32.0/test.rc2/) · [Bitcoin Core 32.0 testing request](https://github.com/bitcoin/bitcoin/issues/36315) · [Release schedule](https://github.com/bitcoin/bitcoin/issues/35122)
## 4. A new BIP addresses multisig backup recovery
**BIP138**, highlighted by Bitcoin Optech on September 25, specifies a way to encrypt **non-seed wallet data**, including descriptors and wallet policies.
One goal is to let a multisig cosigner recover the information needed to reconstruct a wallet using their own seed, without first collecting every other cosigner’s key.
Recovering that wallet information does **not** remove the wallet’s signing requirements. A 2-of-3 multisig still needs two valid signatures to spend.
There is also an important limit: the encrypted backup must **never contain private keys**. Its confidentiality depends on keeping the relevant extended public keys private.
For multisig users, the proposal addresses a real backup problem, but it is a specification rather than a reason to change an existing wallet setup immediately.
**Sources:** [BIP138 — original specification](https://github.com/bitcoin/bips/blob/master/bip-0138.md) · [Bitcoin Optech explanation](https://bitcoinops.org/en/newsletters/2026/09/25/)
## What matters this week?
The clear action item is for **Core Lightning operators to review the security release**.
Bitcoin Core 32.0 is still being tested. Post-quantum Lightning and BIP138 are developments to follow as their designs and implementations progress.
This first edition includes recent September developments to establish the starting point for the series.
**What development are you watching most closely: Lightning security, post-quantum research, or the next Bitcoin Core release?**
---
*Bitcoin Thursday is a weekly look at Bitcoin’s technical developments.*
*There is no order without chaos!*
<center>

[](https://satsman.com?ref=chaosmagic23&c=grow-your-army)
[](https://witness.the-hive-mobile.app/#/witnesses/@thebbhproject)
<sup>[Vote for the BBH Witness](https://witness.the-hive-mobile.app/#/witnesses/@thebbhproject)</sup> <br>

<sup>chaosmagic23@sats.v4v.app</sup><br>
</center>
*Images and screenshots are from me or AI generated*
<sub>Posted via [HiveSuite](https://hivesuite.app/@chaosmagic23/bitcoin-thursday-october-1-2026-ln0rj6ed)</sub>