Particle.news
Download on the App Store

Core Lightning Tells Operators to Upgrade or Go Offline After AI-Found Bugs

Maintainers plan to release signed binaries under a 14-day source-disclosure embargo to limit attacker reconnaissance.

Overview

  • Core Lightning issued an urgent advisory on Wednesday telling node operators to install a forthcoming security release or shut nodes down or restart them in offline mode to avoid exposure.
  • The team confirmed several real vulnerabilities after reviewing a roughly ten-day surge of AI-generated CVE reports that produced many submissions requiring developer validation.
  • Developers are preparing signed fixed binaries and will withhold source-level details for 14 days while third-party packagers such as Start9 have pushed updates that automatically set nodes to --offline to block peer connections and payments.
  • There are no confirmed fund losses or active exploitations so far, but CLN versions 26.04 and earlier are affected and will not be supported during the emergency response.
  • Public Lightning capacity has already fallen and mass node withdrawals reduce payment routes and liquidity, while running CLN with --offline preserves on-chain channel monitoring but stops routing and income from payments.