started · updated
Core Lightning issues urgent security alert for Bitcoin nodes
Developers of Core Lightning (CLN), a major implementation of the Bitcoin Lightning Network maintained by Blockstream, have issued an urgent security alert following the discovery of multiple vulnerabilities. The flaws were identified through a series of AI-generated vulnerability reports received from various sources over a 10-day period.
To mitigate risk, maintainers are urging node operators to either install an upcoming emergency security release or run their nodes in –offline mode. Using the offline setting allows the daemon to continue monitoring the Bitcoin blockchain while preventing the node from connecting to peers or routing payments. Developers have cautioned against simply shutting down nodes entirely, as this could leave funds vulnerable to malicious force-closing of channels.
As a security precaution, the team plans to release signed binaries first and will withhold the specific source-level patches and technical details for 14 days. This embargo is intended to prevent attackers from reverse-engineering the fixes to develop new exploits. Currently, there are no confirmed reports of fund losses or active exploitation of these specific vulnerabilities.
Entities
Bitcoin · Bitcoin Lightning Network · Blockstream · Christian Decker · Core Lightning · OpenSats
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The Bitcoin Lightning Network capacity has decreased by approximately 32.1% over the last eight months. bitcoinethereumnews.com · cryptonomist.ch
- [● 2 SOURCES] Operators unable to upgrade immediately are advised to use the –offline option to prevent peer connections and payments. crypto.news · www.blocktempo.com
- [● 2 SOURCES] Developers will withhold source-level patches for 14 days to prevent attackers from reverse-engineering exploits. bitcoinethereumnews.com · u.today
- [● 4 SOURCES] There have been no confirmed reports of fund losses or active exploitation of these vulnerabilities. bitcoinethereumnews.com · crypto.news · cryptonomist.ch · news.bitcoin.com
- [● 3 SOURCES] The vulnerabilities were identified following a series of AI-generated vulnerability reports received over a 10-day period. bitcoinethereumnews.com · crypto.news · u.today
- [● 4 SOURCES] Core Lightning developers have urged node operators to either install an upcoming security release or take their nodes offline. bitcoinethereumnews.com · crypto.news · news.bitcoin.com · u.today
- [● 2 SOURCES] Operators who cannot immediately upgrade are advised to use the –offline option to prevent peer connections and payments. crypto.news · www.blocktempo.com
- [● 4 SOURCES] Core Lightning developers have urged node operators to install an upcoming security release or disconnect their nodes from the network. bitcoinethereumnews.com · crypto.news · news.bitcoin.com · u.today