Bitcoin Lightning Security Alert: Core Lightning Tells Nodes to Upgrade or Shut Down

A wave of AI-generated bug reports has triggered a Bitcoin Lightning security alert that developers are calling urgent, pushing Core Lightning to warn node operators they must upgrade their software or shut their systems down entirely. The warning, issued after the project received several automated vulnerability submissions within a single 10-day window, lands at a moment when the broader Lightning Network is already shrinking, with public channel capacity down roughly a third since late last year.
Key takeaways
- Core Lightning developers are telling node operators to upgrade to a new security release or take their nodes offline.
- The alert follows multiple AI-generated vulnerability reports received over a 10-day span from different sources.
- Source-level details of the flaws will stay private for 14 days so attackers can’t reverse-engineer exploits before patches spread.
- Bitcoin Lightning Network capacity has fallen about 32.1%, dropping from 5,891 BTC to 3,998 BTC over eight months.
- No confirmed fund losses or active attacks have been reported so far.
Urgent Security Warning for Core Lightning Nodes
Core Lightning, one of the major implementations powering Bitcoin’s Lightning Network, is asking node operators to move fast: either install an incoming security release or disconnect their nodes from the network until it’s ready. That’s the core of the current Bitcoin Lightning security alert, and it stems from an unusual source — not a traditional security researcher, but a cluster of automated bug reports.
… Continue reading the full article at the original source below.



