Overview
- Core Lightning issued an urgent advisory on Wednesday telling node operators to install a forthcoming security release or shut nodes down or restart them in offline mode to avoid exposure.
- The team confirmed several real vulnerabilities after reviewing a roughly ten-day surge of AI-generated CVE reports that produced many submissions requiring developer validation.
- Developers are preparing signed fixed binaries and will withhold source-level details for 14 days while third-party packagers such as Start9 have pushed updates that automatically set nodes to --offline to block peer connections and payments.
- There are no confirmed fund losses or active exploitations so far, but CLN versions 26.04 and earlier are affected and will not be supported during the emergency response.
- Public Lightning capacity has already fallen and mass node withdrawals reduce payment routes and liquidity, while running CLN with --offline preserves on-chain channel monitoring but stops routing and income from payments.