Core Lightning Urges Node Operators to Go Offline Due to Vulnerability

Core Lightning Urges Node Operators to Go Offline Due to Vulnerability

First seen 27 Aug 2026, 14:16 UTC CryptorankBitbobitcoinworld.co.in 72.0

Article Content

Browse articles
ThreatCluster

Core Lightning (CLN) disclosed a critical vulnerability affecting all nodes running version 26.04 or earlier, urging operators to take their nodes offline immediately. The vulnerability poses a high risk of fund loss and routing disruption, potentially undermining the security of the Lightning Network. A two-week embargo on technical details has been placed to allow operators time to prepare for a patch, which is expected to be released within 48 hours. Developers recommend that those unable to upgrade should restart their nodes in offline mode to prevent transactions while keeping the daemon active. No confirmed fund losses or active attacks have been reported, indicating a preemptive response. This incident comes amid a decline in public channel capacity on the Lightning Network, which has dropped by approximately 32.1% since late December 2025. The vulnerabilities were identified following multiple AI-generated CVE reports received over a 10-day period. The urgency of the situation highlights the challenges of maintaining secure decentralized infrastructure.

Key Points: • Core Lightning nodes running version 26.04 or earlier are vulnerable. • Operators are urged to take nodes offline due to high risk of fund loss. • A patch is expected within 48 hours, but details are under a two-week embargo.

Timeline

2026-08-17
AI-generated CVE reports received
Core Lightning received multiple AI-generated vulnerability reports over a 10-day period, prompting a review.
Bitbo
2026-08-27
Core Lightning discloses vulnerability
Core Lightning advises all node operators running version 26.04 or earlier to take their nodes offline due to a critical vulnerability.
Cryptorank
2026-08-27
Patch expected within 48 hours
Core Lightning developers announced plans to release signed binaries containing fixes within 48 hours, with source-level patches under embargo for two weeks.
Bitbo