Core Lightning Urges Node Operators to Shut Down Amid Security Advisory

iconCryptoBriefing
Share
AI summary iconSummary
Core Lightning urged full node operators to shut down on August 26 due to a critical vulnerability. No patched version is available for CLN 26.04 or earlier. The advisory followed AI-generated CVE reports exposing exploitable flaws. Maintainers are preparing a fix but have placed a two-week embargo. Start9 released an update to disable incoming connections. A separate LND flaw has raised concerns about node decentralization and Lightning Network security.

Core Lightning, the Lightning Network implementation maintained by Blockstream, issued an urgent advisory on August 26 telling node operators to take their nodes offline immediately. The catch: the patched version hasn’t been released yet, meaning operators can’t upgrade even if they want to. Their only option right now is pulling the plug.

Any node running CLN version 26.04 or earlier is affected, and those versions will no longer receive support. The maintainers say signed binaries for a fixed release are being prepared, but the specific vulnerabilities will remain under a two-week embargo.

What triggered the advisory

The disclosure came after CLN developers received a flood of AI-generated CVE reports over a ten-day period. CVEs, or Common Vulnerabilities and Exposures, are the standardized way security researchers flag software flaws. Receiving a burst of them, especially ones generated by AI tools rather than human researchers, apparently surfaced real exploitable issues in the process.

Advertisement

The team hasn’t published technical details, which is standard practice for critical vulnerabilities where immediate exploitation is possible. The two-week embargo gives operators time to patch before attackers can reverse-engineer the fix to understand the flaw.

Third parties are already responding

Start9, which provides self-hosted server software including Lightning node packages, released CLN package version 26.6.6 on August 26. The update automatically puts CLN nodes into offline mode, disabling incoming connections and Lightning payment functionality.

The approach preserves on-chain funds and channel states. Lightning channels involve funds locked in multisignature Bitcoin transactions. Going offline doesn’t mean losing money, it means temporarily losing the ability to route payments or earn routing fees.

Lightning’s fragility on display

On the same day CLN issued its advisory, a separate vulnerability disclosure surfaced for LND, the competing Lightning implementation developed by Lightning Labs. That flaw affects LND versions prior to 0.21.0.

Having both major Lightning implementations face security disclosures simultaneously puts Lightning Network’s resilience as a whole into question. CLN and LND together represent the vast majority of Lightning Network capacity.

Lightning Network nodes going offline en masse will reduce available payment routes and liquidity across the network. Payments that would normally succeed by hopping through multiple well-connected nodes may fail or require higher fees to find alternative paths.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.