Core Lightning developers have issued an emergency security warning to Lightning Network node operators after a wave of AI-generated reports uncovered multiple genuine vulnerabilities. The team is keeping the technical details confidential for two weeks while developers work on fixes and give operators time to update their systems.
Core Lightning, or CLN, has told operators not to switch off their machines. If an immediate upgrade is not possible, they should restart their nodes using the --offline option. This prevents the node from communicating with other Lightning participants while keeping the software running.
The Lightning Network operates above Bitcoin and enables users to make relatively fast, low-cost BTC payments without recording every individual transfer directly on Bitcoin’s base layer. CLN is one of the main software implementations used to operate Lightning nodes and route payments.
CLN developers said they began receiving a large number of vulnerability reports generated by AI models in early August. Each report identifies a potential security problem that developers must investigate and reproduce before determining whether it poses an actual threat.
The team said several of the reported weaknesses were confirmed. Developers are now using a two-week disclosure window to prepare patched releases and allow operators to secure their nodes before attackers can access the technical details.
Why Operators Are Being Told to Keep Nodes Running
The warning circulated widely across Bitcoin social media on Thursday, but parts of the original instruction were misinterpreted. CLN initially advised operators who could not upgrade immediately to restart their nodes with --offline rather than powering them down.
The developers later stressed that shutting down a node entirely is not recommended. A Lightning node that is no longer running cannot watch the Bitcoin blockchain or respond to potentially harmful activity involving its payment channels.
Lightning channels work by allowing participants to lock BTC together and update their balances repeatedly without publishing every payment to the blockchain. When the channel closes, its final balance is settled on Bitcoin.
Nodes must remain active to monitor the blockchain for a counterparty attempting to close a channel using an outdated state. If that occurs, the node can respond onchain to protect its funds.
A machine that has been completely turned off cannot perform that monitoring.
The --offline option offers a safer alternative for operators waiting to patch. It cuts the node’s connections to other Lightning nodes, preventing it from sending, receiving or routing payments. However, CLN continues running and can still monitor the Bitcoin blockchain.
Core Lightning plans to distribute signed patched versions before releasing detailed information about the vulnerabilities. Operators will be able to verify the authenticity of the software before installing it.
The developers have not disclosed how many vulnerabilities were identified, what specific actions attackers could take or whether any of the flaws have been exploited. The normal Core Lightning 26.09 release remains scheduled for late September.
Another Lightning Security Incident in August
The latest warning is the second major Lightning security emergency reported this month.
Earlier in August, a vulnerability in BTCPay Server exposed credentials used to control Lightning nodes. Attackers reportedly exploited the weakness to drain funds from some affected nodes before a patch was released. BTCPay developers later said AI was altering the balance between attackers and defenders and issued bounties to researchers who discovered the flaw.
AI is increasingly being used to audit Bitcoin-related software as well. In late July, the 16-member Bitcoin Red Team used AI models to examine 390 Bitcoin repositories, producing nearly 5,000 findings, including 85 classified as critical, in about 27 hours.
Separately, a group that included Coinbase, Block, BitGo, Blockstream and the Bitcoin Policy Institute asked AI companies in August to give Bitcoin developers early access to their most capable models. The group argued that defenders need access to advanced AI tools if attackers are already able to use them.





