Back to top
  • 공유 Share
  • 인쇄 Print
  • 글자크기 Font size
URL copied.

Core Lightning Issues Emergency Bitcoin Security Warning

Core Lightning Issues Emergency Bitcoin Security Warning. Source: Image by Gerd Altmann from Pixabay

Core Lightning developers have issued an emergency security warning to Bitcoin Lightning Network node operators after a surge of AI-generated vulnerability reports uncovered several genuine software flaws.

The team behind Core Lightning (CLN), one of the main software implementations powering Bitcoin Lightning Network payments, advised operators not to shut down their machines. Instead, users unable to immediately install upcoming security fixes should restart Core Lightning using the --offline mode.

This setting disconnects a node from other Lightning Network participants, preventing it from sending, receiving or routing Bitcoin payments. Crucially, however, the software continues running and monitoring the Bitcoin blockchain, helping protect BTC locked in payment channels.

Lightning channels allow participants to lock Bitcoin and conduct multiple off-chain transactions before recording the final balance on Bitcoin. Nodes must remain active because they monitor the blockchain for attempts by counterparties to close channels using outdated balances. A powered-off node cannot detect or respond to such activity.

Core Lightning said its small development team began receiving large volumes of AI-generated security reports in early August. After reviewing the findings, developers confirmed that several vulnerabilities were legitimate.

Technical details are being withheld for roughly two weeks while patches are prepared and operators are given time to upgrade. Core Lightning plans to distribute signed versions of the updated software first, allowing users to verify that the files came directly from the development team. Vulnerability details and source code are expected after the embargo.

Developers have not disclosed the number or severity of the vulnerabilities, what attackers could potentially accomplish, or whether any flaws have already been exploited. The regular Core Lightning 26.09 release remains scheduled for late September.

The warning marks the second major Lightning Network security incident in August. Earlier this month, a BTCPay Server vulnerability exposed credentials controlling Lightning nodes, allowing attackers to steal funds from some affected systems.

AI is increasingly influencing Bitcoin cybersecurity. The Bitcoin Red Team recently used AI models to examine 390 Bitcoin-related repositories, generating nearly 5,000 findings in roughly 27 hours, including 85 classified as critical. The growing use of advanced AI tools by both security researchers and potential attackers is increasing pressure on Bitcoin infrastructure developers to identify and patch vulnerabilities quickly.

<Copyright ⓒ TokenPost, unauthorized reproduction and redistribution prohibited>

Most Popular

Comment 0

Comment tips

Great article. Requesting a follow-up. Excellent analysis.

0/1000

Comment tips

Great article. Requesting a follow-up. Excellent analysis.
1