Summary

  • Core Lightning has acknowledged that various security flaws highlighted in AI-generated reports are genuine.
  • The team has urged operators to quickly verify and implement an upcoming update.
  • For those unable to upgrade, operators are advised to use the --offline mode instead of shutting down their nodes, according to Core Lightning.

In a recent post on X, the developers behind Core Lightning, the Bitcoin payment software, alerted node operators about several legitimate vulnerabilities identified in a series of AI-generated security assessments. They indicated that a coordinated fix is underway.

Operators have been instructed to promptly install and verify the upcoming update, or alternatively, to switch their nodes to offline mode to maintain monitoring of payment channels instead of shutting them down entirely.

Myriad: What's next for Bitcoin prices? Make your prediction!

Core Lightning emphasized that using the offline mode prevents peer connections, which means no payments can be processed through the node. The software will continue to monitor the blockchain, allowing it to respond if a channel is force-closed by a counterparty. In contrast, a powered-off node cannot perform these functions, making shutdown a less favorable option.

Core Lightning specializes in software that facilitates Bitcoin payments via the Lightning Network, a second-layer solution aimed at accelerating transaction speeds. The team has reportedly spent weeks analyzing a significant number of AI-generated Common Vulnerabilities and Exposures (CVE) reports that detail potential software weaknesses.

While the project has not disclosed the number of confirmed vulnerabilities or the potential actions an attacker could take, it has stated that specifics will remain confidential for at least two weeks as developers prepare fixes and operators implement updates.

“When the release is available, ensure you verify the signatures and install it promptly, rather than delaying,” Core Lightning added in a follow-up post.

🟥 URGENT: Critical vulnerability in Core Lightning

Blockstream developers recommend that users immediately shut down their CLN Lightning nodes!

Spread the word! pic.twitter.com/4HpobzMs7Y

— calle 🟥 (@callebtc) August 26, 2026

In another update on the Core Lightning Discord, the team disclosed that its “small crew and external contributors” dedicated ten days to assess AI-generated vulnerability reports from various sources and develop fixes. Initially, they intended to release a point update shortly but later decided to distribute signed, reproducible binaries while keeping the details confidential for two weeks, during which they strongly advised operators to upgrade.

Reasons Against Shutting Down

The Core Lightning team advised those unable to upgrade to restart their nodes in offline mode, which restricts payments and connections to other Lightning nodes while still allowing monitoring of Bitcoin transactions. They also announced that support for older versions, including 26.04, would be discontinued, with version 26.09 expected to be released in late September.

Myriad: When is OpenAI's GPT-6 expected? Make your prediction!

Monitoring is essential since Lightning channels process payments off the Bitcoin blockchain and settle on it when closing. Keeping the node’s software active enables it to respond if a partner forces the closure of a channel.

“This is why we recommend it over shutting down: an active daemon continues to track the blockchain and can react if a counterparty force-closes, while a stopped one cannot,” Core Lightning explained on X.

AI's Role in Identifying Bitcoin Software Flaws

This warning comes in the wake of reports from other Bitcoin firms and developers indicating that AI has uncovered security vulnerabilities throughout the ecosystem.

In July, Coinkite, a hardware wallet manufacturer, suggested that an attacker may have utilized AI to analyze legacy software code, exposing a flaw in the Coldcard wallet's seed generation, which is critical for controlling funds. This vulnerability was linked to the theft of millions of dollars in Bitcoin. Earlier this month, Boltz, a Bitcoin swap service, announced a temporary halt to its operations, citing that attackers were discovering vulnerabilities faster than its developers could address them.

According to the Bitcoin Red Team, a group of cybersecurity and blockchain specialists, AI-assisted audits have yielded 4,962 potential vulnerabilities across 390 Bitcoin projects. Of these, 85 were deemed critical and 635 highly severe, though some may be false positives.

Calle, a pseudonymous Bitcoin developer and member of the Bitcoin Red Team, stated that the group aims to identify weaknesses before they can be exploited by attackers.

“At this stage, it's a race against time,” Calle told Decrypt. “The existence of the Bitcoin Red Team is crucial for preempting attackers as swiftly as possible.”

Calle, who also contributes to the Cashu digital cash protocol, noted that AI has simplified the process for individuals lacking security expertise to exploit software flaws.

“Basic exploits can now be executed from start to finish by someone without the necessary knowledge, thanks to AI,” he remarked.

Daily Debrief Newsletter

Start each day with the latest news stories, along with original features, podcasts, videos, and more.