Core Lightning (CNL) developers have urged node operators to switch to offline mode if they are not prepared to update to an upcoming client release that has not yet been made public. This information was reported by The Defiant.
Core Lightning is a widely-used implementation of the Bitcoin Lightning Network micropayment protocol, developed and maintained by Blockstream.
The publication cites a message shared in the team's Discord channel, which was later reposted by an anonymous user on stacker.news.
The initial message, dated August 13, indicated that the CLN team had received numerous AI-generated security reports.
"We are currently developing a broader strategy to address vulnerabilities. The first step is a point release containing several fixes, and we strongly recommend updating to this version," the message stated.
A subsequent message urging operators to disable outdated nodes was posted on August 23. The team announced that they would release binaries addressing various identified vulnerabilities but would not disclose specific details about the fixes.
"Release details will remain under embargo for two weeks. Executable files will include signatures from the team to verify reproducibility," CLN noted.
Developers also mentioned that previous releases, including 26.04, would no longer be supported. The release of version 26.09 is still anticipated by the end of September.
No Updates Yet
As of August 27, CNL had yet to publish binaries or a security notice. The last release in the team's repository was on July 22.
No updates have been posted on the project's GitHub security advisory page either. Official accounts for Core Lightning and Blockstream have not commented on the issue.
The warning has largely been disseminated through third parties. Bitcoin Core contributor Mark Erhardt confirmed the authenticity of the message on the Discord server.
"I received confirmation from one of the CLN developers that this is true, and [validators] should take action," he added.
In a separate post on X, Erhardt noted that a "serious" issue had been discovered, advising operators to consider restarting the client with the --offline parameter and to monitor for the point release.
The message gained more traction when a Bitcoin developer known as calle highlighted the security issue in a more urgent tone.
"Urgent! Critical vulnerability in Core Lightning. Developers strongly urge users to immediately disable CLN Lightning nodes! Please spread the word!" the post read.
It is worth noting that on August 25, Cosmos Labs called for a halt to EVM networks following attacks on three blockchains.
