
Core Lightning confirms security flaws
- Core Lightning confirmed multiple vulnerabilities in its Bitcoin Lightning Network software.
- Operators are urged to install a forthcoming security update.
- Those unable to upgrade can restart nodes with
--offlineas a temporary measure.
Core Lightning confirmed multiple vulnerabilities and urged node operators to install a forthcoming security update.
The project said it found several genuine flaws while reviewing a high volume of AI-generated vulnerability reports.
Operators who cannot upgrade can restart nodes with --offline to block payments and routing.
Core Lightning has not disclosed the flaws’ nature, severity or CVE identifiers, and reported no related losses.
The project said offline nodes can still follow the Bitcoin blockchain and respond to forced channel closures.
The confirmed flaws are separate from remote denial-of-service issues disclosed in May and July.
Core Lightning is an open-source implementation of the Bitcoin (CRYPTO:BTC) Lightning Network, a system designed for faster off-chain payments.

