Core Lightning Confirms Undisclosed Vulnerabilities, Advises Nodes to Update or Go Offline
The Core Lightning team reviewed AI-generated security reports and confirmed real bugs in some of them. Fixes are being prepared under an embargo of about two weeks.

Core Lightning vulnerabilities were confirmed by the team behind this Lightning Network implementation after it reviewed AI-generated CVE reports from multiple sources. The project said the review took approximately ten days and found real security bugs in some reports. Node operators were advised to update promptly once fixes are released or switch to --offline mode.
The warning concerns Core Lightning software, also known as CLN, and does not confirm a bug in the Bitcoin protocol or in the entire Lightning Network. As of August 27, 2026, the project had not disclosed the number of bugs found, affected versions, technical parameters, or their severity.
Core Lightning vulnerabilities remain under embargo for now
Core Lightning is preparing binaries containing fixes. It plans to keep details about the bugs and the fixes’ source code under an embargo of approximately two weeks. This approach limits publicly available information before operators have an opportunity to deploy the update.
The project has therefore not yet published CVE identifiers or an exact list of affected releases. It is not known which configurations may be vulnerable or what conditions potential exploitation would require.
Core Lightning also has not confirmed active exploitation of the bugs. There is no public evidence that the incident led to stolen funds or other financial losses. The claim that this involves one critical bug therefore does not match the project’s announcement: it refers to multiple real vulnerabilities without providing a severity assessment.
What the --offline switch means
For nodes that cannot update immediately, Core Lightning recommends launching with the --offline switch. The mode stops Lightning connections and payments. However, it does not shut down the node: the process remains running and continues to monitor the Bitcoin blockchain.
For operators, this means they will not be able to send or route Lightning payments through that node while using this mode. This is a temporary operational restriction recommended until fixes are released and verified, not a description of a technical solution to a specific bug.
AI reports were reviewed for approximately ten days
The CLN team said it reviewed reports created with the help of AI from multiple sources. It confirmed that some described real problems. However, the public announcement does not indicate which specific AI systems created the reports or whether AI was the original discoverer of every subsequently confirmed bug.
The event highlights the practical side of coordinated security-bug remediation: developers first validate reports, prepare fixes, and only then publish technical information. In this case, it is therefore important to distinguish confirmed bugs in one implementation from claims that Bitcoin or the entire Lightning network has been compromised.
What CLN operators should expect
- signed and reproducible binaries containing fixes, along with precise instructions from Core Lightning,
- a list of affected versions, CVE identifiers, and a severity assessment,
- technical details about exploitation possibilities after the embargo ends,
- any credible confirmation of active exploitation or financial losses,
- publication of the fixes’ source code and the complete security advisory approximately two weeks later.
Until these details are published, the extent of the risk to users’ funds cannot be quantified. The confirmed information remains that Core Lightning identified several real, currently undisclosed vulnerabilities and provided operators with a temporary mode that limits Lightning communication.
Sources
- Core Lightning message reproduced on Stacker News – Contains an announcement attributed to the CLN team: validation of AI-generated reports, preparation of fixes, a two-week embargo, and the –offline recommendation.
- Decrypt – Corroborates that Core Lightning publicly confirmed multiple real reports, recommended updating or using –offline, and did not disclose details or the exploitation status.
- CoinDesk – Corroborates that technical parameters and the status of possible exploitation were not disclosed, and explains how –offline mode works.
- ElementsProject/lightning – Confirms that Core Lightning is an ElementsProject project and a publicly maintained software implementation of the Lightning Network.
Verified and updated: 08/27/2026 20:32



