Core Lightning Warns Node Operators of Security Flaws
Core Lightning has identified multiple security vulnerabilities in its Bitcoin Lightning Network software and urged node operators to install an upcoming security update or temporarily run their nodes offline.
The project confirmed several vulnerabilities after reviewing a large number of AI-generated CVE reports, but has not disclosed the severity of the flaws, assigned public CVE identifiers, or reported evidence of exploitation or related losses.
Node operators were advised to prioritize upgrading to the patched software and use the, offline option as a temporary measure until they can install the update. This setting prevents the node from connecting to peers and stops payments from entering, leaving, or routing through it, but allows the daemon to continue monitoring the Bitcoin blockchain.
Core Lightning emphasized that operators should not simply stop the software because an active daemon can continue following the Bitcoin blockchain and respond if another party force-closes a Lightning channel. A fully stopped node cannot perform the same monitoring while it remains offline.