NG Solution Team
Cybersecurity

Core Lightning issues urgent security alert after AI reports

Core Lightning developers issued an emergency warning to node operators after confirming that several vulnerabilities flagged in a wave of AI-generated security reports are real. Operators were told to install a forthcoming security update promptly once it becomes available, or restart their nodes with the –offline flag if they cannot upgrade immediately; the project warned explicitly not to power down the machine.

Core Lightning’s guidance and why –offline matters

The project explained that the –offline flag “stops peer connections, so no payments route in, out or through your node,” while keeping the node running so it continues to watch the blockchain and can still act if a counterparty force-closes a channel. The developers warned that a node that is powered off cannot do that, which is why switching off is the worse option.

How the review began and what is known

The security review started after Core Lightning’s small development team received a large volume of AI-generated Common Vulnerabilities and Exposures reports from multiple sources over a concentrated ten-day period in August. The team, assisted by outside contributors, validated submissions and developed fixes during that period. Several of the AI-generated reports turned out to identify genuine problems.

The project has not disclosed how many flaws were confirmed, what an attacker could do with them, or whether anyone has exploited them. Those details will remain private for at least two weeks while developers prepare fixes and operators update their nodes.

Distribution, embargo and release status

Core Lightning plans to distribute signed, reproducible binaries carrying the fixes so operators can verify the files came from the development team before installing them. The project expects to publish the source code and technical details of the vulnerabilities after the two-week (fourteen-day) embargo window closes.

Developer Christian Decker said the delay is intended to prevent researchers from using comparisons between patched code and earlier releases to develop working attacks before users have upgraded; the fourteen-day embargo is meant to provide a deployment window for node operators. The project has also withdrawn support for older releases, explicitly including version 26.04. The latest publicly tagged build before the emergency binaries was Core Lightning v26.06.6, and version 26.09 remains scheduled for late September.

Related posts

How vulnerable is Latvia’s strategic infrastructure to cyberattacks?

Jessica Williams

Is the PTZOptics Studio 4K Camera Redefining Box Cameras?

Emily Brown

Has Lemonade Insurance agreed to a $10.5M settlement over a data breach?

David Jones

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy