The Bitcoin Lightning Network implementation, Core Lightning (CLN), has issued a security advisory urging node operators to upgrade as soon as a patched version is released; if upgrading is not immediately possible, operators should consider taking their nodes offline. The team has not disclosed details of the vulnerability, but a security response has been initiated.
Received multiple reports within 10 days
Core Lightning is developed and maintained by Blockstream. The project team states that over the past 10 days, multiple AI-generated vulnerability reports have been received from various sources, and developers and open-source contributors are verifying whether these issues are valid.
The team originally planned to release a minor update within a few days to directly fix the related issues, but later adjusted the resolution approach.
Release the patch first
Core Lightning has decided to initially provide signed binary patches, while keeping information related to the vulnerability confidential for two weeks. Developers state that this approach aims to reduce the risk of attackers reverse-engineering the patch to identify the vulnerability and develop exploitation tools.
The project maintainers strongly recommend that all users complete the upgrade during the confidentiality period. For operators who have not upgraded, the team recommends at least restarting the node. Previous versions, including 26.04, will no longer receive support during this security response.
The community questions the communication approach.
Calle, a developer associated with the Cashu ecosystem, referred to the issue as a critical vulnerability and urged Core Lightning node operators to shut down their nodes immediately. Some community members questioned why users first learned about the incident through screenshots of Discord messages rather than an official announcement from the project’s verified account.
Following external concerns, Core Lightning subsequently issued an official warning to node operators. However, as of now, the team has not disclosed the specific type or actual severity of the vulnerability.

