Core Lightning urges immediate node shutdown after AI CVEs

Core Lightning maintainers reported AI-generated CVE reports that revealed multiple vulnerabilities and told node operators to shut nodes and wait for signed patches within 48 hours.

Core Lightning maintainers warned that AI-generated CVE reports exposed several vulnerabilities in the software and urged node operators to shut down Lightning nodes immediately. The team expects to publish signed patched binaries within 48 hours and plans full technical disclosure within two weeks.

The developers are preparing signed binaries to address the flaws and recommended taking current CLN instances offline so they stop communicating with other nodes until the update is applied. At the time of the notice there were no confirmed reports of funds lost or active exploitation tied to the disclosed bugs.

On social media, developer Calle posted: ‘Critical vulnerability in Core Lightning. Blockstream developers urge users to shut down CLN Lightning nodes right NOW! Please let everyone know.’ Another contributor, Murch, wrote at 1:41 p.m. EDT that ‘Looks like a severe Core Lightning (CLN) issue’ and advised operators to consider restarting nodes while offline to prevent network connections. A member of the community using the name Cobra Bitcoin reacted: ‘Wtf is happening. This is really scary.’

Core Lightning is Blockstream’s implementation of the Lightning Network software used to route off-chain Bitcoin payments. Public channel capacity on the Lightning Network was about 3,998 BTC as of Wednesday at 5 p.m. EDT, valued at roughly $313.5 million. That level represents a decline of 1,893 BTC, or 32.1%, since Dec. 27, 2025, when capacity measured about 5,891 BTC.

The disclosure follows other incidents where AI tools were reported to have played a role in finding or assisting exploits, including a Coldcard firmware vulnerability that preceded losses of nearly 2,000 BTC and a series of attacks that prompted a swaps platform to suspend service. Those incidents affected multiple dependent services.

Maintainers advised operators not to attempt manual mitigations that keep nodes connected. Operators who cannot stop service immediately were told to isolate CLN instances from the network and avoid opening or accepting new channels until the official signed binaries are published. The team asked users to share the shutdown notice with other node operators to limit exposure until the fix is available.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author