A series of vulnerabilities have been discovered in the Lightning Network that require immediate intervention. Developers of Core Lightning (CLN) — one of the key implementations of the second-layer payment protocol for bitcoin — have confirmed the issues and are already preparing an update that will close the discovered gaps. However, technical details will only be disclosed after users install the fixes.

AI attacks on bitcoin infrastructure

The situation escalated on August 13, when the project team reported a wave of vulnerability reports received over the past 10 days. Notably, a significant portion of these reports was generated by artificial intelligence. A small group of developers and volunteers manually filtered real bugs from the noise, and as it turned out, not in vain — some messages were confirmed, turning routine maintenance into a full-fledged coordinated security release. The initial idea of releasing a "quick patch" version was abandoned in favor of a more thorough approach.

This is not the first time bitcoin infrastructure has come under attack. Earlier in August, BTCPay Server warned operators to urgently update due to a vulnerability that allowed attackers to drain user funds through credential manipulation. Shortly before that, an exploit was recorded in the Coldcard hardware wallet.

Two-week delay and risks for operators

Details of the vulnerabilities are intentionally not being disclosed. According to the public report, attackers could quickly assemble a working exploit, so the team will first release the patched software and publish a full description of the issues only after the update has been installed. All new builds are signed by developers, allowing external observers to verify the release against the source code. The fixes close most of the identified vulnerabilities.

Regular Lightning users, unfortunately, cannot influence the situation — their payments pass through nodes operated by other people, and the speed of the update depends solely on operators. For those who fail to update in time, there is a fallback option: the node can be temporarily shut down, which will disconnect it from the network, but the background daemon process will continue running, monitoring the blockchain and responding to payment channel closures.

As Lightning's popularity grows, so do the risks. The technology has already been integrated into non-custodial mobile wallets and payments within messengers, so a routing failure now affects far more users.

Blockstream CEO Adam Back regularly engages in public debates about the direction of bitcoin development, but it is precisely this kind of unnoticed technical work that remains in the shadows. Nodes left unupdated and connected to the network pose a real threat to the entire ecosystem.

My analysis: The fact that AI is now being used to generate vulnerability reports is an alarming signal. This means attacks are becoming more automated and widespread, and developers have to spend resources filtering out junk instead of directly fixing code. Node operators should view this update not as a recommendation, but as a mandatory condition for continuing to work with the network.