AdvertisementAdvertisementAdvertisementAdvertisement
Cryptocurrency

Core Lightning Developers Urge Node Operators to Update

8/29/2026, 03:34 PM • Evgenia Sliv

(edited: 08/29/2026)

Core Lightning Developers Urge Node Operators to Update

The Core Lightning development team has reported receiving numerous vulnerability reports generated using artificial intelligence technologies. Core Lightning is a software implementation of the Lightning Network for the Bitcoin network — an open-source project developed with the support of the community and Blockstream. Over the past ten days, developers have received a significant number of automatically generated CVE reports, some of which have been confirmed as genuine and may pose certain risks to network security.

Information about the need to update nodes first appeared in the project's Discord channel and was subsequently confirmed on Core Lightning's official page on the social network X. Developers noted that they are working on a comprehensive strategy to address the discovered vulnerabilities. The first step will be the release of an interim update for nodes. Operators are advised to either update their software to the latest version or take their nodes offline until the patch is released.

To put a node into safe mode, developers recommend restarting it with the --offline flag. This command halts peer connections and stops routing payments through the node, but allows it to continue monitoring the state of the network and to operate correctly during forced channel closures. This approach provides the minimum functionality required for channel state monitoring while simultaneously reducing the risk of vulnerability exploitation.

The official statement emphasizes that older versions of the software will not be supported, making the update critical for all node operators. Meanwhile, the scheduled release planned for the end of September will proceed on its established timeline regardless of the current security situation. Detailed information regarding the discovered vulnerabilities will be disclosed by the developers after a two-week publication embargo, which is standard practice in the cybersecurity industry to prevent premature exploitation of vulnerabilities by malicious actors.

The Core Lightning situation reflects a broader trend in the cybersecurity industry. As more advanced AI models are released, the number of automatically discovered vulnerabilities is growing — including in already active or even discontinued projects. Reports have previously emerged of $2 million being stolen from the Aztec Connect protocol, also linked to the exploitation of vulnerabilities in smart contracts. The growing capabilities of AI tools for automated code auditing are creating new challenges for developers, who must respond swiftly to an increasing flow of reports about potential security issues.

Popular news