Critical Vulnerabilities Found in Bitcoin's Lightning Network

iconBitMedia
Share
AI summary iconSummary
Bitcoin news: Critical vulnerabilities have been discovered in the Lightning Network, exposing users to the risk of fund loss. Nodes running versions 26.04 and earlier are affected. The team advises halting routing and payment processing or switching to offline mode. A CVE identifier has been assigned, but details remain undisclosed. A two-week moratorium provides operators time to apply patches. This follows a July AI audit that uncovered nearly 5,000 security issues, including 85 critical flaws. A network upgrade is expected to mitigate these risks.

Developers believe the vulnerability could lead to user fund losses. All nodes running versions 26.04 and above are at risk. As an immediate measure, the project team recommends suspending routing and payment processing. For those unable to fully shut down their node, it is advised to restart the background process with the “offline” parameter. This mode disables connectivity with other Lightning Network nodes—payments cannot be sent, received, or routed—but the software will continue running and monitoring the Bitcoin blockchain.

Screenshot 2026-08-27 at 17.22.16.png

The vulnerability has been assigned a CVE identifier, but experts have not yet clarified the technical details of the flaw. A two-week embargo on reporting the issue is intended to give operators time to apply patches before attackers can analyze the changes.

Screenshot 2026-08-27 at 17.22.28.png

This is not the first time AI has detected flaws in the Bitcoin network. At the end of July, a group called Bitcoin Red Team, comprising 16 developers, used AI models to analyze 390 Bitcoin project repositories and announced that they had identified nearly 5,000 security issues, 85 of which were classified as critical and 635 as high-severity vulnerabilities. However, no detailed descriptions of the vulnerabilities were provided.

The Lightning Network operates on top of the Bitcoin blockchain, enabling faster transactions with lower fees by not recording every payment on the main chain. To do this, two participants lock a certain amount of bitcoins into a shared payment channel and repeatedly update the distribution of funds between them. When the channel is closed, the final balance is recorded on the blockchain. A node must continuously monitor the network: if the other party attempts to close the channel using outdated data, the node can respond on the blockchain to secure its funds. A completely powered-off machine cannot do this.

Previously, Charles Guillemet, Chief Technology Officer of hardware wallet manufacturer Ledger, stated that a vulnerability affecting clear signing in the Ethereum app had been patched. The flaw was discovered by the Ledger Donjon team using an AI-powered vulnerability detection system.


Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.