Core Lightning Warns Node Operators of Multiple Vulnerabilities
Core Lightning, an open-source implementation of Bitcoin's Lightning Network, has confirmed multiple vulnerabilities and urged node operators to install a forthcoming security update. The project assessed a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports and found that several are real.
Core Lightning advised operators not to shut down their nodes completely, but to restart them with '--offline,' which prevents payments from entering, leaving or routing through the node.
The guidance gives operators an alternative for protecting their nodes until they upgrade, without shutting down the underlying software entirely. Core Lightning has not disclosed the nature or severity of the vulnerabilities, published CVE identifiers or reported any related exploitation or losses.