Core Lightning Advises Node Operators to Restart With Offline Flag Amid Security Flaws
Core Lightning, an open-source Bitcoin project, has confirmed security flaws in its code after receiving AI-generated vulnerability reports over the past ten days.
The team has been working to validate and triage these reports, with some of them being real security flaws. To address this issue, Core Lightning is advising node operators not to shut down their nodes but instead restart them with the, offline flag.
This flag blocks payments from routing through the node, but keeps the daemon running so it can still watch the chain and respond if a channel partner force-closes. The team emphasizes that a fully powered-off node cannot defend against such an attack.
Core Lightning plans to publish signed binaries within the next few days, with full technical details embargoed for two weeks after that. In the meantime, operators should keep their nodes running with the, offline flag and wait for further instructions.