AI vulnerability reports identified a critical flaw in Bitcoin Lightning Network; developers confirmed the issues and are preparing fixes.
Tech & Launches ·
Core Lightning, the developers of Bitcoin payments software, confirmed that several vulnerabilities flagged in AI-generated security reports are real and announced they are coordinating fixes. The project urged node operators to install forthcoming updates promptly, warning that those unable to upgrade should run their nodes offline using the --offline flag rather than powering them down entirely. Keeping nodes running allows them to monitor the blockchain and respond if a counterparty forces a channel closure, functionality a powered-off node cannot perform.
Core Lightning's team spent around ten days reviewing a high volume of AI-generated vulnerability submissions from multiple sources before deciding to distribute signed, reproducible binaries while keeping technical details under embargo for at least two weeks. The project has not disclosed how many flaws were confirmed, what capabilities attackers could gain, or whether any have been exploited in the wild. Version 26.04 and earlier will no longer receive support, while version 26.09 remains scheduled for late September.
It remains unclear whether the vulnerabilities affect other Lightning implementations, how widespread operator compliance will be, or what the timeline looks like once the two-week embargo lifts and details become public.