Core Lightning Developers Order Node Shutdowns Due to Unspecified Vulnerability
Core Lightning developers have instructed node operators to shut down their systems immediately due to an undisclosed security vulnerability. The team has stated that until a patch is released, operators should run their nodes with the, offline flag or shut them down altogether.
The instruction was issued on August 26, but precompiled binaries containing the fix were not available for public download at the time. The latest stable release in the project's GitHub repository is v26.06.6, which was published on July 22.
This incident marks the fourth security alert affecting Bitcoin infrastructure within a four-week period, following issues with Coldcard, Boltz, and BTCPay Server. To protect the network from potential exploit vectors, the team has decided to keep the precise description of the vulnerabilities under embargo for two weeks.