Core Lightning Issues Emergency Warning Amid Surge of AI-Generated Vulnerability Reports
Core Lightning developers have issued an emergency warning to Bitcoin Lightning Network node operators after discovering several genuine software flaws, some of which were uncovered through AI-generated vulnerability reports. The team behind Core Lightning (CLN), one of the main implementations powering Bitcoin Lightning Network payments, has advised operators not to shut down their machines due to the ongoing security threat.
The developers plan to distribute signed versions of the updated software first, allowing users to verify that the files came directly from the development team. Vulnerability details and source code are expected after a two-week embargo, during which time patches are being prepared and operators are given time to upgrade.
This warning marks the second major Lightning Network security incident in August, following an earlier BTCPay Server vulnerability that exposed credentials controlling Lightning nodes, allowing attackers to steal funds from some affected systems. The use of AI is increasingly influencing Bitcoin cybersecurity, with the recent example of the Bitcoin Red Team using AI models to examine 390 Bitcoin-related repositories, generating nearly 5,000 findings in roughly 27 hours, including 85 classified as critical.