The Core Lightning (CLN) development team has confirmed the discovery of a number of vulnerabilities in its implementation of Bitcoin's Lightning Network payment layer. An update with fixes will be released in the coming days, but technical details will only be disclosed two weeks later.
The Essence of the Problem
Lightning Network enables instant Bitcoin payments outside the main blockchain, using a network of channels between nodes. Until operators install the patch, funds in these channels are protected only by code whose weaknesses the team already knows about. This is a classic race against time: attackers could exploit the breach before operators manage to update.
AI Attacks and a Wave of Reports
Core Lightning is one of the key implementations of the Lightning Network, developed by Blockstream and running on Bitcoin's mainnet since 2018. On August 13, the team reported that over the previous 10 days it had received numerous vulnerability reports generated by artificial intelligence. A small group of developers and volunteers manually separated real bugs from the noise.
Some of the reports were confirmed, so routine maintenance turned into a coordinated security release. The team abandoned its initial plan to quickly release a "patch" in favor of a more thorough approach.
Bitcoin infrastructure has not been attacked for the first time this year. In August, BTCPay Server warned operators of the need for an urgent update: attackers drained user funds through a vulnerability in credential handling. And an exploit in the Coldcard wallet occurred a few days earlier.
Two-Week Delay
Details of the vulnerabilities are deliberately not being disclosed. According to the public vulnerability report, attackers could quickly assemble a working version to carry out an exploit. Therefore, the team will first release the fixed software, and publish a full description only after the update.
All updates are signed by developers. This confirms build reproducibility, and external observers can verify the release against the source code. The fixes close most of the vulnerabilities from the reports.
What Operators Should Do
Regular Lightning users cannot influence the situation: their payments go through nodes managed by other people, and the speed of updates depends on operators. Those who do not update immediately have a fallback option. The node can be temporarily shut down — it will then disconnect from the network, but the background daemon process will continue to run. This is a program in the background that monitors the blockchain and triggers when a payment channel is closed.
As Lightning's popularity grows, so do the risks. The technology has already been integrated into non-custodial mobile wallets and payments within messengers, so now a routing failure affects more users.
Blockstream CEO Adam Back regularly engages in public disputes about the directions of Bitcoin scaling development. Unlike his loud statements, the quiet technical work rarely attracts the attention of a mass audience. Nodes left unupdated and connected to the network pose risks.
My analysis: This situation is another reminder that Lightning Network security critically depends on the discipline of node operators. As the technology scales, every unpatched node becomes a potential entry point for attacks. Investors and users should closely monitor updates from their providers, because in the world of cryptocurrencies, a delay of a couple of days can cost the loss of funds.