The Core Lightning (CLN) team, Blockstream's flagship implementation of the Lightning Network protocol, has issued an urgent warning for node operators. The message's essence is extremely blunt: if you are not ready to immediately install a not-yet-released patch, take your nodes offline. This is not a recommendation, but effectively a security requirement.

Incident timeline: from AI reports to forced offline mode

The first notice appeared on August 13 in the project's official Discord channel. CLN representatives reported receiving a batch of AI-generated vulnerability reports. At that time, the team announced a "point release" with fixes, strongly urging operators to prepare for the update.

However, by August 23, the tone had changed dramatically. Developers stated they were publishing binary files with fixes, but vulnerability details would remain under embargo for at least two weeks. The key point: all previous versions, including the then-current 26.04, were declared unsupported. The scheduled version 26.09 is still expected by the end of September, but the situation has clearly spiraled beyond the planned release cycle.

Lack of a public patch and insider confirmation

As of August 27, neither binary files nor an official security notice have appeared in the GitHub repository. The last public release is dated July 22. The official Core Lightning and Blockstream accounts remain silent, which in itself is an alarming signal for the market.

Information is spreading through third parties. Bitcoin Core project contributor Mark Erhardt publicly confirmed the authenticity of the Discord messages, stating he personally received confirmation from a CLN developer. He recommends operators restart clients with the --offline flag and watch for the point update release. A Bitcoin developer under the pseudonym calle went further, characterizing the situation as a "critical vulnerability" and calling for the immediate shutdown of all nodes.

This incident fits into a worrying trend: last week, Cosmos Labs already called for halting EVM networks after a series of attacks on three blockchains. The CLN situation shows that even the most mature second-layer protocols are vulnerable, and the practice of "silent patches" with delayed information disclosure is becoming the new norm. Node operators should view this as a signal to reassess their own incident response protocols, not as a one-off threat.