Core Lightning Confirms Vulnerabilities, Urges Node Upgrades

Core Lightning Confirms Vulnerabilities, Urges Node Upgrades

Core Lightning is preparing a security release after confirming several vulnerabilities identified through a recent wave of AI-generated vulnerability reports. The Lightning Network implementation is advising node operators to upgrade promptly once signed binaries are published, while operators who cannot upgrade immediately are advised to restart with the –offline flag. Core Lightning says technical details of the vulnerabilities will remain under embargo for two weeks, with fuller information to follow afterward. The current release is v26.06.6, and earlier versions including 26.04 are unsupported. At present, the public information does not establish the vulnerabilities’ severity, specific attack methods, or whether any have been exploited. Core Lightning’s regular 26.09 release remains planned for late September.

Core Lightning Confirms Vulnerabilities Following AI-Generated Reports

Core Lightning said it has been triaging a high volume of AI-generated CVE reports in recent weeks, working with open-source contributors to verify, classify and address the findings. In one of its updates, the project said several of the reports were genuine and that a coordinated fix was underway. 

The project later provided more context on the reporting process, saying the volume of AI-generated reports had prompted additional review before the issues were confirmed.  The wording does not establish that AI independently discovered the vulnerabilities. Instead, it indicates that AI-generated reports were submitted to the project and subsequently assessed by maintainers and contributors. WuBlockchain reported that Core Lightning has chosen to withhold the technical details for about two weeks while the fix is prepared. The project says signed binaries will be published first, followed by source code and reproducible builds that allow the changes to be independently checked.  The staged approach leaves gaps in the public record. Core Lightning has not published the specific vulnerabilities, their attack vectors or a severity assessment, and nothing released so far confirms exploitation or user losses.

Core Lightning is an open-source Lightning Network implementation maintained by Blockstream, in use on Bitcoin mainnet since 2018. The project’s GitHub releases page currently lists v26.06.6 as its latest published release, with the release carrying a verified signature. Core Lightning has separately said that previous releases, including 26.04, are unsupported and that the 26.09 release remains planned for late September.

Operators Advised to Upgrade or Go Offline

Core Lightning’s immediate recommendation is for operators to upgrade once the security release becomes available. The project says users should verify the signatures of the published binaries before installing them. Operators who cannot upgrade immediately do not need to shut nodes down entirely. Instead, they should restart Core Lightning using the –offline option.

The distinction matters. The –offline flag closes peer connections, so payments cannot route into, out of or through the node. The daemon itself remains active, allowing it to continue following the Bitcoin blockchain and respond if a counterparty force-closes a Lightning channel. A completely stopped node cannot perform those functions while it is powered off.  Core Lightning has stressed that upgrading remains the preferred option. Operators should also remove the flag after installing the update so the node can reconnect to its peers.

Users running Core Lightning through platforms such as Umbrel or Start9 may need to set the flag as a startup option rather than a dashboard toggle. For now, the response remains focused on limiting node exposure while giving operators time to install the forthcoming fix. The technical details of the vulnerabilities are expected after the two-week embargo, which should provide more information about their nature and potential impact. Until then, the available evidence supports describing the incident as a security issue affecting Core Lightning software, rather than as a confirmed compromise of Bitcoin or the Lightning Network itself.