< Back to all clusters
[TECHNOLOGY] · 13 sources

started · updated

Core Lightning issues urgent security alert for Bitcoin nodes

Developers of Core Lightning (CLN), a major implementation of the Bitcoin Lightning Network maintained by Blockstream, have issued an urgent security alert following the discovery of multiple vulnerabilities. The flaws were identified through a series of AI-generated vulnerability reports received from various sources over a 10-day period.

To mitigate risk, maintainers are urging node operators to either install an upcoming emergency security release or run their nodes in –offline mode. Using the offline setting allows the daemon to continue monitoring the Bitcoin blockchain while preventing the node from connecting to peers or routing payments. Developers have cautioned against simply shutting down nodes entirely, as this could leave funds vulnerable to malicious force-closing of channels.

As a security precaution, the team plans to release signed binaries first and will withhold the specific source-level patches and technical details for 14 days. This embargo is intended to prevent attackers from reverse-engineering the fixes to develop new exploits. Currently, there are no confirmed reports of fund losses or active exploitation of these specific vulnerabilities.

Entities

Bitcoin · Bitcoin Lightning Network · Blockstream · Christian Decker · Core Lightning · OpenSats

Claims

What the coverage asserts, and how many sources carry each claim.

Sources