Core Lightning Warns of Security Vulnerabilities
Core Lightning (CLN) node operators are being urged to disconnect from peers as developers prepare signed binaries containing fixes for undisclosed security vulnerabilities. Bitcoin developer Calle amplified the warning on August 26, urging CLN operators to take affected nodes offline until patched software is available.
The vulnerabilities have not been linked to confirmed thefts or exploitation in the wild and technical details will remain under embargo for two weeks while patched binaries are distributed. Core Lightning plans to distribute reproducible signed binaries carrying fixes for vulnerabilities identified during a recent wave of security reports.
Operators who do not upgrade are being told to restart their nodes with the --offline flag, cutting peer connectivity while preserving access to the node. The project has also withdrawn support for older releases, explicitly including version 26.04. The latest publicly tagged build remained Core Lightning v26.06.6 before the emergency binaries were released.
Running offline does not simply shut down lightningd; the node can continue following Bitcoin and deal with channel state locally, including force-close handling, while external Lightning peer connections remain disabled. Core Lightning 26.09 remains scheduled as the next major release after the emergency security work.