Skip to content
Core Lightning Urges Node Operators Offline Due to Vulnerabilities

Core Lightning Urges Node Operators Offline Due to Vulnerabilities

First seen 27 Aug 2026, 14:16 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 28, 2026 at 13:53 UTC
  • •Core Lightning advises immediate offline operation for nodes running version 26.04 or earlier.
  • •A patch is expected within 48 hours, but technical details are under a two-week embargo.
  • •No confirmed exploitation has been reported, but the vulnerabilities pose a high risk to funds.

Core Lightning has disclosed multiple vulnerabilities affecting all nodes running version 26.04 or earlier, urging operators to take their nodes offline immediately. The vulnerabilities were identified through AI-generated CVE reports, and while a patch is expected within 48 hours, a two-week embargo on technical details is in place. Operators are advised to use the --offline mode to keep their nodes active without routing transactions, as stopping the node entirely would prevent monitoring of the Bitcoin blockchain. No confirmed exploitation has been reported, but the urgency of the advisory suggests a significant risk of fund loss and network disruption. The incident highlights ongoing challenges in maintaining secure decentralized infrastructure, particularly as public channel capacity on the Lightning Network has declined significantly over the past months.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-05-05
CVE-2024-52911 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-27
Core Lightning discloses vulnerabilities
Core Lightning confirms multiple vulnerabilities affecting nodes running version 26.04 or earlier, urging immediate offline operation.
Cryptorank
2026-08-27
AI-generated CVE reports reviewed
Developers reviewed AI-generated CVE reports and confirmed several real issues that need fixing.
Kucoin
2026-08-27
Patch expected within 48 hours
Core Lightning developers plan to release signed binaries with fixes within 48 hours, holding back source-level patches for two weeks.
Bitbo

More articles in this cluster (7)

Following this threat?

Track Core Lightning and CVE-2024-52911 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed