The situation surrounding the second most popular Lightning Network implementation — Core Lightning (CLN) — is taking an alarming turn. Developers of the project, backed by Blockstream, have urgently recommended that node operators take their nodes offline if they are unable to immediately update to a patch that has not yet been released. This is an unprecedented step, indicating the seriousness of the discovered issues.
The Essence of the Warning
The first notice appeared on August 13. Team representatives reported receiving numerous AI-generated security reports and announced the development of a comprehensive strategy to address vulnerabilities. A key element of this strategy was to be a point release with fixes, which all operators were strongly urged to install.
However, ten days later, on August 23, the tone of the messages shifted to a more categorical one. The team stated that the publication of binary files with fixes was imminent, but the details of the vulnerabilities and the fixes themselves would be under strict embargo for two weeks. It was also clearly stated that all previous versions, including the then-current 26.04, would no longer receive support.
Silence on the Airwaves
The most alarming aspect is the absence of any official publications. As of August 27, neither binary files nor an official security bulletin have appeared. The project's GitHub repository has not been updated since July 22, and the security page is empty. Neither Core Lightning nor Blockstream has made official statements on their social media channels.
Information is spreading through third parties, which adds uncertainty. However, authoritative ecosystem participants, including Bitcoin Core contributor Mark Erhardt, have confirmed the authenticity of the Discord messages. Erhardt characterized the issue as "serious" and advised operators to restart their nodes with the --offline flag while awaiting the patch. A Bitcoin developer under the pseudonym calle went even further, calling the vulnerability "critical" and urging immediate node shutdowns.
This situation is reminiscent of recent events in Cosmos, where critical issues were also discovered. However, in the case of Lightning Network, where user funds in channels are at stake, the cost of an error could be particularly high.
My analysis: The "silence" strategy with an embargo on details is a double-edged sword. On one hand, it prevents the creation of exploits in the immediate aftermath. On the other, the absence of an official patch and clear instructions amid such loud warnings creates panic and distrust. Node operators who cannot afford downtime are now forced to make difficult decisions in an information vacuum. This is a serious blow to the project's reputation, and how quickly and transparently the fixing release is issued will determine how strong that blow turns out to be.