The situation around one of the key implementations of the Lightning Network is heating up. The Core Lightning (CLN) development team has issued an urgent warning to node operators: those who are unable to immediately upgrade to the upcoming release with fixes are strongly advised to switch their nodes to offline mode. This is not a routine update, but a forced security measure prompted by discovered vulnerabilities.
The essence of the warning and timeline of events
The first notice appeared on the team's official Discord channel as early as August 13. At that time, CLN representatives reported receiving a batch of AI-generated security reports and announced the development of a strategy to address the issues. However, the key signal came on August 23, when developers stated they were preparing a point release with binary files fixing a number of critical bugs. At the same time, details of the fixes are deliberately kept under embargo for two weeks after publication.
An important nuance: support for previous versions, including release 26.04, is being completely discontinued. The developers emphasize that the new version 26.09, scheduled for the end of September, will not resolve the current issues — operators need to wait specifically for the interim patch.
Lack of public artifacts and community reaction
As of the time of analysis, August 27, the situation remains tense. Despite the loud statements, the CLN team has not yet published either the fixed binary files or an official security notice. The latest available release in the repository dates to July 22, and the security page on GitHub contains no fresh updates. The project's official accounts and Blockstream remain silent, which is generating a wave of rumors and speculation.
Information is spreading mainly through third parties. Well-known Bitcoin Core contributor Mark Erhardt confirmed the authenticity of the Discord messages, noting that he received personal confirmation from a CLN developer. He advises operators to restart the client with the -offline flag and to closely monitor the release of the patch. Bitcoin developer under the pseudonym calle went even further, characterizing the issue as a "critical vulnerability" and urging the immediate shutdown of all CLN nodes.
My analysis: This kind of "radio silence" tactic with a delayed patch release is standard practice to prevent exploits before users have time to update. However, the two-week embargo on details is a double-edged sword. On one hand, it provides time for updates. On the other, it keeps operators in the dark about the real extent of the threat. Given that CLN is one of the most popular implementations of the Lightning Network, a potential hole could affect a significant portion of the network. I recommend that all operators take the warning as seriously as possible and not neglect offline mode if there is no way to instantly install the update.