Bitcoin Lightning Users Face Urgent Warning Over Core Lightning Flaw
Developers of Core Lightning (CLN), a prominent Lightning Network implementation maintained by Blockstream, have issued an urgent security warning to node operators. The alert follows the receipt of multiple AI-generated vulnerability reports submitted by various sources over a ten-day period. In response, maintainers and open-source contributors have been working to validate the undisclosed flaws and deploy remediation measures. To manage the security risk, the Core Lightning team announced a mitigation strategy that involves releasing pre-compiled, signed binaries while placing the underlying source code patches under a 14-day embargo. According to lead developer Christian Decker, withholding the source code is intended to prevent malicious actors from reverse-engineering the fixes to develop working exploits before node runners have upgraded. Ecosystem developers, including Cashu developer Calle, described the issue as a critical vulnerability and strongly urged operators who cannot immediately upgrade to shut down their nodes or take them offline. Unsupported older versions, including v26.04, remain vulnerable, underscoring short-term operational risks across the Bitcoin layer-2 ecosystem.