Lightning Nodes Face Urgent Update as Vulnerabilities Exposed
Core Lightning has confirmed multiple vulnerabilities in its implementation of the Bitcoin Lightning Network and is urging node operators to update their nodes as soon as possible. The project received several AI-generated Common Vulnerabilities and Exposures (CVE) reports from different sources over a 10-day window, which upon review, revealed that some of them are real.
The developers recommended that operators who cannot upgrade immediately restart their nodes with the “, offline” flag, which prevents payments from entering, leaving, or routing through the node while keeping the daemon active. This is necessary because a fully stopped node cannot monitor the Bitcoin blockchain or respond if a counterparty force-closes a channel.
The alert comes at an awkward moment for Lightning, as public channel capacity has fallen from 5,891 BTC in late December 2025 to 3,998 BTC as of Wednesday, a decline of roughly 32.1% over eight months.