Core Lightning Issues Security Alert, Urges Users to Upgrade

icon币界网
Share
AI summary iconSummary
Core Lightning has issued a security breach alert, urging node operators to perform a network upgrade as soon as a fix is available. Those unable to upgrade are advised to take their nodes offline. The team has not disclosed the vulnerability but has released signed binary patches. A two-week delay in public disclosure is intended to reduce the risk of exploitation. Older versions, including 26.04, will no longer be supported. Some users criticized the lack of an official announcement, as initial updates appeared first on Discord. Developers are still verifying AI-generated reports received over the past 10 days.
CoinDesk reports:

The Bitcoin Lightning Network implementation, Core Lightning (CLN), has issued a security advisory urging node operators to upgrade as soon as a patched version is released; if upgrading is not immediately possible, operators should consider taking their nodes offline. The team has not disclosed details of the vulnerability, but a security response has been initiated.

Received multiple reports within 10 days

Core Lightning is developed and maintained by Blockstream. The project team states that over the past 10 days, multiple AI-generated vulnerability reports have been received from various sources, and developers and open-source contributors are verifying whether these issues are valid.

The team originally planned to release a minor update within a few days to directly fix the related issues, but later adjusted the resolution approach.

Release the patch first

Core Lightning has decided to initially provide signed binary patches, while keeping information related to the vulnerability confidential for two weeks. Developers state that this approach aims to reduce the risk of attackers reverse-engineering the patch to identify the vulnerability and develop exploitation tools.

The project maintainers strongly recommend that all users complete the upgrade during the confidentiality period. For operators who have not upgraded, the team recommends at least restarting the node. Previous versions, including 26.04, will no longer receive support during this security response.

The community questions the communication approach.

Calle, a developer associated with the Cashu ecosystem, referred to the issue as a critical vulnerability and urged Core Lightning node operators to shut down their nodes immediately. Some community members questioned why users first learned about the incident through screenshots of Discord messages rather than an official announcement from the project’s verified account.

Following external concerns, Core Lightning subsequently issued an official warning to node operators. However, as of now, the team has not disclosed the specific type or actual severity of the vulnerability.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.