Bitcoin Lightning Network Hit by Real Vulnerabilities as Core Lightning Rushes Patch
Core Lightning (CLN) has confirmed real vulnerabilities in its implementation of the Bitcoin Lightning Network software. The team received a flood of AI-generated bug reports around August 13, which led to a coordinated security release.
The developers sorted through the reports and found several that held up as legitimate bugs. As a result, they dropped their original plan for a quick patch update and are now working on a more comprehensive fix.
The updates will be released within days, but technical details of the vulnerabilities will remain secret until early September. The team is withholding this information to prevent attackers from building exploits based on the publicly disclosed bugs.
Until node operators install the fixes, funds parked in Lightning channels remain exposed, creating an immediate security risk for Bitcoin crypto payments and broader Lightning adoption.