AI Bug Reports Trigger Emergency Warning for Bitcoin Lightning Node Operators
A security warning has been issued to operators of Bitcoin Lightning nodes after AI-generated bug reports uncovered several vulnerabilities in the Core Lightning software.
The developers behind Core Lightning, a key component of the Lightning Network, began receiving a flood of automated vulnerability reports in early August. While some were found to be false alarms, a few genuine weaknesses were discovered that could potentially be exploited by attackers.
The development team has advised node operators not to shut down their machines but instead restart them in a special mode called '--offline', which disconnects the node from other Lightning nodes while keeping it running. This will prevent any potential attacks until patches can be applied and distributed.
This is the second security emergency for the Lightning Network this month, following a flaw in BTCPay Server that exposed credentials controlling nodes and led to funds being drained from some of them.