πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
Bitcoin

Core Lightning Confirms AI-Found Bugs and Holds Details for 14 Days

28 Aug 2026by CryptoJazz Admin1 min read2 views

Core Lightning, one of the main implementations of Bitcoin's Lightning Network, has confirmed that several vulnerabilities reported to it through AI-generated security submissions are real. Operators were told to install a signed release as soon as it appears and, if they cannot wait, to restart their nodes with the --offline flag. Details and source code stay embargoed for fourteen days, so the fix reaches operators before an attacker can read the diff. No CVE numbers, severity ratings or counts have been published. Nobody has reported a loss.

Offline is not off

The distinction matters more than it sounds. A node that is powered down cannot watch the Bitcoin chain, so it cannot respond if a channel counterparty tries to force-close on stale terms and walk away with funds. Running with the flag keeps the daemon alive and blind only to peers, which means no payment routes in, out or through it. Operators have to remove the flag after upgrading, or the node stays cut off. The team put its own position plainly.

"To be clear about what we are recommending: you do not need to shut your node down."

Its instruction, carried by Cryptopolitan and The Crypto Times, was to upgrade with signed binaries when the release is published, or start the node offline.

Two readings of one advisory

Coverage split on Thursday over what operators had been told. Crypto Economy headlined that Core Lightning was urging node operators to shut down immediately. TFTC described the maintainers' directive as taking nodes offline and ceasing to peer with the network. Cryptopolitan and The Crypto Times reported the opposite emphasis, with the team pushing back on the shutdown calls. The underlying instruction is the same in every account. The headlines are not, and they do not reconcile.

The Cashu developer known as calle posted on Wednesday that Blockstream developers were urging users to shut their nodes down at once, and the Bitcoin developer Murch wrote the same day that a severe issue had been found and nodes should consider restarting offline. Christian Decker, Core Lightning's lead maintainer, is quoted by The Crypto Times calling the shutdown advice the kind of panic the team had hoped to avoid. That characterisation appears in one outlet. Disclosure disputes have been a recurring feature of this month, and Ledger and an outside researcher fell out over the terms of one on Tuesday.

Why the source code stays hidden

A published patch is also a published map. Core Lightning is shipping signed binaries first and holding the source and the technical write-up for fourteen days, on the reasoning that a public diff would let an attacker build an exploit faster than operators can patch. CryptoSlate's arithmetic puts the end of the embargo at about 6 September.

Version v26.06.6, published on 22 July, is the current public release, and anything at v26.04 or older is no longer supported. CLN 26.09 is still on the late-September roadmap. The advisory's own date is reported two ways: CryptoSlate dates the binaries announcement to 23 August, while Crypto Economy and TFTC put the alert on 26 August. Signed binaries were described as arriving within roughly 48 hours of that alert. None had been reported as published at the time of writing.

The reports came from a machine

The bugs surfaced from a flood of AI-generated CVE reports that arrived through August from several sources. Most such reports are noise. This batch was not, and a small group spent about ten days separating real findings from the rest. The sweep behind it is on record: the Bitcoin Red Team's audit of 390 open-source repositories returned 4,962 findings in 27.5 hours. Bitcoin Magazine counts 85 of those as critical, and Crypto Economy adds 635 more at high severity. Those are different cuts of one dataset, not competing totals.

What operators have is an alert without a shape. There is no count of the bugs, no statement on whether any has been used, and no signed release in hand as of Friday morning. Until then the recommended posture is a node that follows the chain and speaks to nobody.

Read also: A 2021 Firmware Flaw Drains 594 BTC From Coldcard Wallets

← All news