In brief – Core Lightning confirmed that several AI-generated security reports identified real flaws. – The project told operators to verify and install its forthcoming update promptly. – Operators who cannot upgrade should use –offline instead of shutting down their nodes,…
re Lightning said. The developers of Bitcoin payments software Core Lightning warned node operators in an X post on Wednesday that several vulnerabilities flagged in a wave of AI-generated security reports are real and that developers are coordinating a fix
The project told operators to install and verify the forthcoming update promptly—or run their nodes offline if they cannot upgrade instead of shutting them down and leaving their payment channels unmonitored. “That flag stops peer connections, so no payments route in, out or through your node,” Core Lightning wrote. “It keeps running, which means it keeps watching the chain and can still act if a counterparty force-closes a channel. A node that is powered off cannot do that, and that is why switching off is the worse option.” Core Lightning develops software used to send and route Bitcoin payments over the Lightning Network, which acts as a second-layer network and speeds up transactions. Its team said it has spent several weeks reviewing a high volume of AI-generated CVE reports, or submissions describing possible software vulnerabilities.
The project has not revealed how many flaws it confirmed, what an attacker could do with them, or whether anyone has exploited them. It said details will remain private for at least two weeks while developers prepare fixes and operators update their nodes. “When the release lands, verify the signatures and install it, and do that promptly rather than eventually,” Core Lightning said in a follow-up post. 🟥 URGENT: Critical vulnerability in Core Lightning Blockstream developers urge users to shut down CLN Lightning nodes right NOW! Please let everyone know! pic. — calle 🟥 (@callebtc) August 26, 2026 In a…