Core Lightning developers have issued an emergency warning to Lightning Network node operators after a wave of AI-generated security reports revealed several genuine vulnerabilities. The team is withholding technical details for two weeks to give operators time to install fixes before the weaknesses become public.
Core Lightning, or CLN, advised operators not to shut down their machines. Instead, those who cannot immediately upgrade should restart their nodes using the --offline mode, which disconnects the software from other Lightning nodes while keeping it active.
The Lightning Network operates on top of Bitcoin and enables faster, lower-cost BTC payments without recording every transaction individually on the Bitcoin blockchain. Core Lightning is one of the primary software implementations used to operate nodes that process and route Lightning payments.
The CLN development team said it began receiving a surge of vulnerability reports generated by AI models in early August. These reports identify potential weaknesses that developers must then investigate to determine whether they can actually be exploited.
According to the team, several of the reported issues proved to be genuine. Developers are keeping information about the vulnerabilities private for two weeks while preparing patched software, allowing node operators to update their systems before potential attackers can examine the flaws.
Why Lightning Node Operators Should Stay Online
The warning initially circulated across Bitcoin social media on Thursday, but some details were misunderstood as the message spread. CLN’s original guidance told operators who could not immediately upgrade to restart their nodes with --offline rather than shutting them down.
Developers later emphasized that machines running Lightning nodes should not be powered off completely. A stopped node cannot monitor its payment channels or respond to attempts that could put its bitcoin at risk.
Lightning operates through payment channels in which participants lock BTC and repeatedly update their respective balances. When a channel is eventually closed, its final state can be settled on the Bitcoin blockchain.
Nodes must continuously monitor the Bitcoin network because a channel participant could attempt to close a channel using an older balance. If that happens, the other node can take action onchain to protect its funds.
A powered-down machine, however, cannot detect such an event or respond to it.
Running Core Lightning with --offline provides a different outcome. The setting cuts the node’s connections to other Lightning participants, preventing it from sending, receiving or routing payments, while allowing the software to remain operational and continue monitoring the Bitcoin blockchain.
Core Lightning plans to distribute signed patched releases first. This will allow operators to confirm that the software packages came from the development team before installing them. The source code and technical information about the vulnerabilities are expected to become public once the two-week disclosure period ends.
The project has not revealed what the vulnerabilities could enable attackers to do, how many flaws are involved or whether any of them have been exploited. The regularly scheduled Core Lightning 26.09 release is still expected toward the end of September.
Second Lightning Security Emergency This Month
The latest warning marks the second major Lightning-related security incident reported this month.
Earlier in August, a vulnerability in BTCPay Server exposed credentials used to control Lightning nodes. Attackers reportedly exploited the weakness and drained funds from some affected systems before a patch became available. BTCPay developers later said AI was shifting the balance between security researchers and attackers and awarded bounties to researchers who identified the issue.
Separately, the Bitcoin Red Team, a group of 16 developers, used AI models in late July to scan 390 Bitcoin repositories. The effort produced nearly 5,000 findings, including 85 classified as critical, in roughly 27 hours.
In another August development, a group involving Coinbase, Block, BitGo, Blockstream and the Bitcoin Policy Institute called on AI companies to provide Bitcoin developers with early access to their most capable models. The group argued that developers should not be excluded from AI programs that potential attackers can already access.

More Stories
Bitcoin Faces Major $80K Supply Wall as ETF Holders Near Break-Even
Bitcoin Holds Above $79K as ETF Inflows Extend Longest Run Since April
BlackRock’s Mitchnick: Bitcoin’s Macro Story Grows Stronger After Record Trading