The Core Lightning (CLN) development team has officially confirmed the discovery of a number of vulnerabilities in its implementation of the Lightning Network protocol. A patch package will be released in the coming days, but technical details will only be disclosed two weeks after the release. This decision is standard practice for responsible disclosure, but it raises important questions about the infrastructure's readiness for new challenges.

Lightning Network, positioned as a solution for instant and cheap bitcoin payments, operates through a network of payment channels between nodes. It is precisely these channels, protected by code, that have become the focus of attackers' attention. The weaknesses, already known to the team, require immediate intervention.

AI in the Crosshairs: A Wave of Reports and Manual Filtering

Core Lightning is one of the key implementations of bitcoin's second layer, developed by Blockstream and running on the mainnet since 2018. On August 13, the team reported that over the past 10 days it had received numerous vulnerability reports generated by artificial intelligence. A small group of developers and volunteers manually separated real bugs from informational noise, confirming that automated systems are already being actively used to find weaknesses in critical infrastructure.

Some reports were confirmed, and routine maintenance escalated into a coordinated security release. The team abandoned the initial idea of quickly issuing a "patch" in favor of a more thorough approach. This is the right decision, but it speaks to the severity of the issues found.

Attacks on bitcoin infrastructure are not uncommon. In August, BTCPay Server had already warned operators of the need for urgent updates due to theft of funds through a vulnerability in handling credentials. And an exploit in the Coldcard wallet occurred just a few days earlier. The situation is clearly escalating.

Two-Week Delay: Why Details Are Being Withheld

Details of the vulnerabilities are deliberately not being disclosed. According to the public report, attackers could quickly assemble a working version to carry out an exploit. Therefore, the team will first release the fixed software, and a full description will be published only after the update. All updates are signed by developers, confirming build reproducibility — external observers will be able to verify the release against the source code. The fixes address most of the vulnerabilities from the reports.

Ordinary Lightning users cannot influence the situation: their payments pass through nodes operated by other people, and the speed of updates depends on operators. Those who do not update immediately have a fallback option — the node can be temporarily shut down, disconnecting it from the network, but the background daemon process will continue to run, monitoring the blockchain and triggering when a payment channel closes.

As Lightning's popularity grows, so do the risks. The technology has already been integrated into non-custodial mobile wallets and payments within messengers, so a routing failure now affects far more users.

Blockstream CEO Adam Back regularly engages in public disputes about the directions of bitcoin scaling. Unlike his loud statements, the unnoticed technical work rarely attracts the attention of a mass audience. Nodes left unupdated and connected to the network represent risks.

My view: This situation is a stark reminder that the security of bitcoin's second layer is a continuous process, not a one-time achievement. The use of AI to find vulnerabilities is a new turn in the arms race, and teams will have to adapt. Node operators should treat any security updates as critical and apply them immediately, rather than after a "stability check."