
Core Lightning is preparing a security release after confirming several vulnerabilities identified through a recent wave of AI-generated vulnerability reports. The Lightning Network implementation is advising node operators to upgrade promptly once signed binaries are published, while operators who cannot upgrade immediately are advised to restart with the –offline flag. Core Lightning says technical details of the vulnerabilities will remain under embargo for two weeks, with fuller information to follow afterward. The current release is v26.06.6, and earlier versions including 26.04 are unsupported. At present, the public information does not establish the vulnerabilities’ severity, specific attack methods, or whether any have been exploited. Core Lightning’s regular 26.09 release remains planned for late September.
Core Lightning Confirms Vulnerabilities Following AI-Generated Reports
Core Lightning said it has been triaging a high volume of AI-generated CVE reports in recent weeks, working with open-source contributors to verify, classify and address the findings. In one of its updates, the project said several of the reports were genuine and that a coordinated fix was underway.
Core Lightning has been triaging a high volume of AI-generated CVE reports over recent weeks. Several are real, and a coordinated fix is underway.
What to do now: do not shut your node down. Restart it with –offline.
That flag stops peer connections, so no payments route in,…
— Core Lightning ⚡️ (@Core_LN) August 26, 2026
The project later provided more context on the reporting process, saying the volume of AI-generated reports had prompted additional review before the issues were confirmed. The wording does not establish that AI independently discovered the vulnerabilities. Instead, it indicates that AI-generated reports were submitted to the project and subsequently assessed by maintainers and contributors. WuBlockchain reported that Core Lightning has chosen to withhold the technical details for about two weeks while the fix is prepared. The project says signed binaries will be published first, followed by source code and reproducible builds that allow the changes to be independently checked. The staged approach leaves gaps in the public record. Core Lightning has not published the specific vulnerabilities, their attack vectors or a severity assessment, and nothing released so far confirms exploitation or user losses.
Core Lightning is an open-source Lightning Network implementation maintained by Blockstream, in use on Bitcoin mainnet since 2018. The project’s GitHub releases page currently lists v26.06.6 as its latest published release, with the release carrying a verified signature. Core Lightning has separately said that previous releases, including 26.04, are unsupported and that the 26.09 release remains planned for late September.
Operators Advised to Upgrade or Go Offline
Core Lightning’s immediate recommendation is for operators to upgrade once the security release becomes available. The project says users should verify the signatures of the published binaries before installing them. Operators who cannot upgrade immediately do not need to shut nodes down entirely. Instead, they should restart Core Lightning using the –offline option.
To be clear about what we are recommending: you do not need to shut your node down.
Our advice is to upgrade. When the release lands, verify the signatures and install it, and do that promptly rather than eventually.
–offline is the alternative for anyone who is not going to… https://t.co/rjq8Haz4pE
— Core Lightning ⚡️ (@Core_LN) August 27, 2026
The distinction matters. The –offline flag closes peer connections, so payments cannot route into, out of or through the node. The daemon itself remains active, allowing it to continue following the Bitcoin blockchain and respond if a counterparty force-closes a Lightning channel. A completely stopped node cannot perform those functions while it is powered off. Core Lightning has stressed that upgrading remains the preferred option. Operators should also remove the flag after installing the update so the node can reconnect to its peers.
Core Lightning has been triaging a high volume of AI-generated CVE reports over recent weeks. Several are real, and a coordinated fix is underway.
What to do now: do not shut your node down. Restart it with –offline.
That flag stops peer connections, so no payments route in,…
— Core Lightning ⚡️ (@Core_LN) August 26, 2026
Users running Core Lightning through platforms such as Umbrel or Start9 may need to set the flag as a startup option rather than a dashboard toggle. For now, the response remains focused on limiting node exposure while giving operators time to install the forthcoming fix. The technical details of the vulnerabilities are expected after the two-week embargo, which should provide more information about their nature and potential impact. Until then, the available evidence supports describing the incident as a security issue affecting Core Lightning software, rather than as a confirmed compromise of Bitcoin or the Lightning Network itself.



