Core Lightning has confirmed multiple vulnerabilities in its Bitcoin Lightning Network software and is preparing a security update. The project told node operators to install the patch once available, offering a temporary offline mode for those who have not yet upgraded.
Core Lightning confirmed on Thursday that it had found real security flaws after reviewing a large volume of AI-generated CVE reports, and it is urging operators to install a forthcoming update. The project has not disclosed the vulnerabilities' severity, published CVE identifiers, or reported any related exploitation or losses.
Rather than shutting nodes down entirely, Core Lightning told operators to restart with the –offline flag while they wait for the patch. In a follow-up post, the project clarified that upgrading remains its primary recommendation, and that running offline is only an alternative for operators who have not yet updated.
Offline mode keeps nodes watching the chain
The –offline setting stops payments from entering, leaving, or routing through a node, but it keeps the daemon running. Core Lightning said an active daemon can still follow the Bitcoin blockchain and respond if a counterparty force-closes a channel, something a fully stopped node cannot do. Operators who use –offline were told to remove it once they upgrade, or their nodes will stay disconnected.
New flaws follow earlier DoS disclosures
The newly confirmed vulnerabilities are separate from the remote denial-of-service bugs disclosed in May and July, which were patched in earlier releases. Those earlier issues involved memory exhaustion in separate daemons: one let a remote peer trigger unbounded memory use in connectd, while another let a peer flood gossipd with channel update messages until the affected machine became unresponsive. Both were resource-exhaustion issues, and Core Lightning has not said whether the newly confirmed flaws involve similar components.
Sources: Cointelegraph.com News, crypto.news
Trading involves risk.