Developers of Core Lightning (CLN), one of the key implementations of the Lightning Network payment protocol, have confirmed the discovery of a number of vulnerabilities in the codebase. Updates closing these gaps are expected to be released in the coming days. However, technical details are deliberately being withheld until the patches are installed.

AI on the Frontline of Cyberattacks

The situation is notable because the trigger for the investigation was multiple vulnerability reports generated by artificial intelligence systems. Over the past ten days, the team received a stream of messages that had to be manually filtered, separating real threats from "noise." Some of the reports were confirmed, turning routine technical maintenance into a full-fledged coordinated security release.

This is not the first incident of its kind this year. Earlier in August, the BTCPay Server payment processor warned operators of the need for urgent updates due to a vulnerability in handling credentials that allowed attackers to withdraw user funds. Slightly earlier, a problem was also discovered in the Coldcard hardware wallet. Bitcoin's infrastructure, and Lightning in particular, is becoming an increasingly attractive target.

Two-Week Delay in Disclosure

The Core Lightning team has decided to abandon the original plan for a quick "patch" release in favor of a more thorough approach. All updates have already been signed by developers, guaranteeing their authenticity and allowing external auditors to verify the release against the source code. The fixes close the vast majority of confirmed vulnerabilities. A full public description of the issues will not appear for at least two weeks, to give node operators time to update.

It is crucial to understand: ordinary Lightning users cannot directly influence the situation. Their payments are routed through nodes managed by other network participants. The speed of update distribution depends solely on operators. For those who cannot update immediately, there is a temporary fallback option—shutting down the node. This will disconnect it from the network, but the background daemon process will continue to monitor the blockchain and properly close payment channels.

With the growing popularity of Lightning, which is already being integrated into non-custodial mobile wallets and messengers, the cost of routing errors increases manyfold. Blockstream CEO Adam Back often talks loudly about scaling, but it is precisely this kind of unnoticed technical work that determines the network's reliability.

My comment: This incident is a stark reminder that the Lightning Network remains a complex and young technology. The fact that AI has become a tool for finding vulnerabilities is a double-edged sword: it can also be used to automate attacks. Node operators should treat every security update as critical rather than postponing it. A delay of a few days could cost the loss of funds.