Meta Force Space
BTC $80,035.00 +2.17% ETH $2,534.50 +3.64% SOL $104.53 +8.83% XRP $1.44 +2.09% BNB $712.62 +2.53% DOGE $0.0889 +3.50%
← Back to the news

Core Lightning tells node operators to upgrade after confirming security flaws

Core Lightning has confirmed multiple security vulnerabilities in its Bitcoin Lightning Network software and has urged node operators to install an upcoming security update or temporarily run their nodes offline.

Summary
  • Core Lightning confirmed several vulnerabilities after reviewing a large number of AI generated CVE reports.
  • Node operators were urged to install the security update, with offline mode offered as a temporary option for those awaiting an upgrade.
  • Running a node offline stops Lightning payments and routing while allowing the daemon to continue monitoring the Bitcoin blockchain.
  • Core Lightning has not disclosed the flaws’ severity, CVE identifiers or any evidence of exploitation or related losses.

Core Lightning said Thursday that its developers had been reviewing a large number of AI-generated Common Vulnerabilities and Exposures reports and confirmed that several submissions identified real problems requiring fixes.

The project advised operators to upgrade as its main recommendation. Operators who have not installed the security release can restart Core Lightning with the –offline option, which prevents the node from connecting to peers and stops payments from entering, leaving or routing through it.

Core Lightning initially described the offline setting as a protective measure while fixes were being prepared, but later clarified that operators should prioritize upgrading once the patched software is available.

Technical details about the newly confirmed vulnerabilities have not been made public. Core Lightning has not disclosed their severity, assigned public CVE identifiers or reported evidence that attackers have exploited the flaws.

Core Lightning nodes can remain active without routing payments

Using the –offline setting allows the Core Lightning daemon to remain active while disconnecting the node from the Lightning Network.

Under the configuration, a node does not accept incoming peer connections or attempt to reconnect with existing peers. Payments therefore cannot move through the affected node while the operator waits to install the security update.

Core Lightning said operators should not simply stop the software because an active daemon can continue following the Bitcoin blockchain and respond if another party force-closes a Lightning channel.

A fully stopped node cannot perform the same monitoring while it remains offline. Channel counterparties can publish transactions to Bitcoin when channels are closed, making continued blockchain monitoring part of normal Lightning node operations.

Once operators have installed the patched version, Core Lightning said they should remove the –offline option before restarting normally. Leaving the setting enabled after the upgrade would keep the node disconnected from its peers and prevent it from sending, receiving or routing Lightning payments.

The recommendation applies while developers address vulnerabilities found during their review of AI-generated security submissions. Core Lightning has not publicly described which components are affected or what conditions would be needed to exploit the confirmed flaws.

The project also has not disclosed whether all supported software versions are affected, leaving operators dependent on the upgrade instructions accompanying the security release.

New Core Lightning vulnerabilities follow earlier DoS fixes

The newly confirmed problems are separate from denial-of-service vulnerabilities disclosed earlier this year that could remotely crash Core Lightning nodes.

Two related flaws involved memory exhaustion inside separate Core Lightning daemons. One affected connectd, the component handling peer connections, while another affected gossipd, which processes network information used by Lightning nodes.

In the connectd case, a remote peer could trigger unbounded memory use and eventually cause an out-of-memory crash. The issue was patched before the latest vulnerability warning.

Another flaw allowed a remote peer to flood gossipd with channel update messages, causing an internal map used for unknown short channel IDs to continue consuming memory until the machine became unresponsive or crashed.

Both problems relied on resource exhaustion, while Core Lightning has not said whether the newly confirmed vulnerabilities involve similar components or attack methods.

Security fixes requiring node operators to install updated software have also appeared elsewhere in Bitcoin infrastructure this year. In May, crypto.news previously reported that Bitcoin Core disclosed a bug that could allow miners to remotely crash vulnerable nodes.

Tracked as CVE-2024-52911, the issue affected Bitcoin Core releases after version 0.14.0 and before version 29.0. Developers had already fixed it in Bitcoin Core 29.0, released in April 2025, before publicly disclosing the vulnerability in May 2026.

The bug involved Bitcoin Core’s script interpreter during block validation. A specially constructed invalid block could cause a node to access data after the relevant memory had been freed, potentially crashing the software. Bitcoin Core said remote code execution was possible but unlikely because of restrictions on block data.

Bitcoin software projects have continued patching node risks

A separate Bitcoin Core privacy flaw was addressed in June through the 31.1rc1 release candidate, alongside changes covering blockchain validation, wallets, networking and MuSig2 security.

The privacy problem affected PrivateBroadcast, a feature designed to reduce the information exposed when transactions are first transmitted. Developers released the fix before the next stable Bitcoin Core version and asked users to test the release candidate before production deployment.

Lightning implementations have faced software-specific problems before as well. In June 2023, operators of Lightning Labs’ LND implementation were warned against upgrading to version 0.16.3 because of a memory leak.

The problem caused the software’s memory use to increase over time and could eventually crash a node. Operators who had already installed LND 0.16.3 were advised at the time to downgrade to version 0.16.2 while developers addressed the issue.

Another Lightning security issue emerged later in 2023 when developer Antoine Riard described replacement cycling attacks that could be used against Lightning payment channels. Riard subsequently stepped back from Lightning Network development after arguing that the problem required changes beyond short-term mitigations.

Riard said at the time that no replacement cycling attacks had been observed or reported in the wild during the preceding 10 months, while a functional test existed for exercising an affected Lightning channel against the Bitcoin Core mempool.

The vulnerability involved replacing an unconfirmed transaction under specific conditions, potentially interfering with the transaction sequence used to protect funds in Lightning channels. Riard said existing mitigations could make attacks harder but did not consider them a permanent solution.

Core Lightning has withheld details of the latest flaws

For the current Core Lightning vulnerabilities, operators have received protective instructions before technical disclosure of the underlying bugs.

The project has said several AI-generated CVE submissions were valid, but it has not published the affected functions, attack paths or conditions needed to reproduce the issues.

No losses or successful attacks have been reported in connection with the newly confirmed flaws based on Core Lightning’s disclosure so far.

Operators who have not yet upgraded were instead instructed to use –offline while keeping the daemon running, allowing the software to continue tracking Bitcoin for channel-related transactions without participating in Lightning payments.

After installing the security update, Core Lightning said operators using the temporary configuration must remove –offline to reconnect their nodes to peers and resume normal payment and routing activity.

Originally published by crypto.news on

Read the original on crypto.news ↗

Text and images are the property of crypto.news and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news