The Core Lightning (CLN) team has confirmed the discovery of a number of vulnerabilities in its implementation of the Lightning Network protocol. An emergency patch will be released in the coming days, and technical details of the issues will only be disclosed after node operators have had time to update.
AI flooded with reports, but the bugs are real
Core Lightning is one of the key implementations of Bitcoin's payment layer, developed by Blockstream and running on the mainnet since 2018. So, on August 13, the team reported that over the past 10 days it had received many vulnerability reports generated by artificial intelligence. A small group of developers and volunteers manually separated the wheat from the chaff — real bugs from the noise.
Some of the reports were confirmed, and planned maintenance turned into a coordinated security release. The initial idea — to quickly release a "patch" — was rejected in favor of a more thorough approach.
This is not the first time this year that Bitcoin infrastructure has been attacked. In August, BTCPay Server had already warned operators about the need for urgent updates: attackers were draining user funds through a vulnerability in credential handling. And an exploit in the Coldcard wallet occurred just a few days earlier.
Two-week delay: why details are being withheld
Details of the vulnerabilities are deliberately not being disclosed. According to the public report, attackers could quickly assemble a working exploit. Therefore, the team will first release the fixed software, and a full description will be published only after the update.
All updates are signed by developers. This confirms the reproducibility of the build, and external observers can verify the release against the source code. The fixes close most of the vulnerabilities from the reports.
Regular Lightning users cannot influence the situation: their payments go through nodes operated by other people, and the speed of updates depends on the operators. Those who do not update immediately have a fallback option — the node can be temporarily shut down, and it will disconnect from the network, but the background daemon process will continue to run. This is a program that monitors the blockchain and triggers when a payment channel closes.
As Lightning's popularity grows, so do the risks. The technology has already been integrated into non-custodial mobile wallets and payments within messengers, so now a routing failure affects more users.
Blockstream CEO Adam Back regularly engages in public disputes about the directions of Bitcoin scaling development. Unlike his loud words, the quiet technical work rarely attracts the attention of the mass audience. Nodes left without updates and connected to the network pose risks.
My analysis: The situation highlights the fragility of even the most advanced second-layer solutions. Until node operators show discipline and install the patches within the next 48 hours, the network remains vulnerable to targeted attacks. This is a serious test of maturity for the entire Lightning community.