The Core Lightning (CLN) development team has confirmed the discovery of a series of vulnerabilities in the Bitcoin Lightning Network codebase. A patch update will be released in the coming days, but technical details will be deliberately disclosed only after two weeks.
Lightning Network, positioned as a solution for instant and cheap bitcoin payments off the main chain, has once again come under the security spotlight. This time, the issues concern one of the key implementations of the protocol — Core Lightning, developed by Blockstream and running on the mainnet since 2018.
AI reports and manual filtering
On August 13, the CLN team reported that over the past 10 days it had received numerous vulnerability reports generated by artificial intelligence systems. A small group of developers and volunteers manually separated real bugs from false positives, and some reports were confirmed. This turned routine maintenance into a full-fledged coordinated security release, abandoning the initial idea of a quick "hot" patch.
It is worth noting that this is not the first incident this year. Earlier, BTCPay Server had already warned operators to urgently update due to the risk of fund theft through a vulnerability in credential handling. Shortly before that, a problem was discovered in the Coldcard hardware wallet that allowed attackers to withdraw funds.
Two-week delay and risks for operators
The details of the vulnerabilities are deliberately not disclosed. According to the public report, attackers could quickly assemble a working exploit, so the team will first release patched software, and a full description of the issues will be published only after operators have had time to update.
All updates will be signed by developers, ensuring build reproducibility and allowing external auditors to verify the release against the source code. The fixes close most of the identified vulnerabilities. Node operators are strongly advised to install the patches immediately. For those who cannot update right away, there is a temporary solution: disconnect the node from the network. In this case, it will disconnect from the network, but the background daemon process will continue to monitor the blockchain and properly close open payment channels.
Regular Lightning users, who use wallets and payments through messengers, cannot influence the speed of the update — it depends entirely on node operators. As the technology grows in popularity, the risks only increase, and routing failures affect more and more people.
Blockstream CEO Adam Back regularly engages in public disputes about bitcoin scaling directions, but it is the unnoticed technical work that rarely attracts mass audience attention. Nodes left unupdated and connected to the network pose a real threat to the entire ecosystem.
My view: The situation demonstrates the maturity of the security process in Lightning, but also highlights the fragility of the network: until operators update, funds in channels remain at risk. This is a reminder that decentralization requires responsibility from every participant in the infrastructure.