Core Lightning Warns Node Operators to Go Offline Due to Unpublished Vulnerability Fixes
Core Lightning has told node operators to take their nodes offline unless they upgrade to a release that has not been published yet. The team said it will publish binaries carrying fixes for many of the reported vulnerabilities while holding back what they fix, keeping the details under embargo for two weeks.
The guidance came in a message circulated in the Core Lightning Discord and reproduced on stacker.news by an anonymous poster. The message said that if operators choose not to upgrade, they should take their node offline. Given the known risks, the team will not support previous releases, including 26.04.
Mark Erhardt, a Bitcoin Core contributor at Localhost Research, confirmed the message was sent by a moderator in the CLN Discord and followed up with a confirmation from one of the CLN maintainers that it is legit and operators should take action.
The CLN team first described the pressure publicly on Aug. 13, saying they received a number of AI-generated CVE reports from multiple sources over the past 10 days. They said then that they were aiming to have a point release out within the next few days, but 13 days later, the plan is binaries under embargo.
Core Lightning runs a share of a network carrying 375,019,291,916 sats, or about 3,750 BTC, across 33,101 channels and 16,420 nodes as of the Aug. 20 snapshot, per mempool.space. The team attributed the reports they are triaging to 'multiple sources' without naming the Red Team.