Core Lightning Issues Urgent Security Alert Amid AI-Generated Bug Reports
A security alert has been issued for Core Lightning nodes on the Bitcoin Lightning Network. Multiple AI-generated bug reports were received by the project over a 10-day period, prompting developers to treat the situation as critical. The exact nature of the vulnerabilities is not yet disclosed, but node operators are being advised to upgrade to a new security release or shut down their nodes entirely.
The alert arrives at a time when the Bitcoin Lightning Network is already experiencing a decline in capacity. According to data from Mempool.space, public channel capacity has dropped by approximately 32.1% over the last eight months, reducing liquidity and usability for users relying on the network for fast, low-cost Bitcoin transfers.
Core Lightning developers are prioritizing speed in their response, with a plan to ship signed binaries containing fixes within about 48 hours. However, source-level details of the vulnerabilities will remain private for 14 days to prevent attackers from exploiting them before most operators have updated.