Core Lightning confirmed real security flaws after a wave of AI-generated vulnerability reports, leaving node operators a two-week window to patch before technical details go public.
Core Lightning confirmed security flaws in its Bitcoin Lightning software Wednesday, urging node operators to upgrade or take nodes offline as capacity fell 32 percent.
"The details of the release will remain under embargo for two weeks," the Core Lightning team said in a message circulated in its Discord and reproduced on stacker.news. "The binaries will be accompanied by the team's signatures confirming reproducibility."
The warning follows a wave of AI-generated vulnerability reports the project received over 10 days beginning early August. A small group of developers and volunteers sorted real bugs from noise, and several reports held up, turning routine cleanup into a coordinated security release. Public channel capacity stood at 3,998 BTC, about $313.5 million, on Wednesday, down from 5,891 BTC on Dec. 27, 2025 — a decline of 1,893 BTC, or roughly 32 percent, per Mempool.space.
The stakes climb as Lightning reaches more users through self-custodial mobile wallets and chat-app payment tools, widening the group exposed to a routing failure. Operators who skip the upgrade can restart nodes with the --offline flag, which disconnects peers while the daemon keeps monitoring the Bitcoin blockchain for channel closures. The embargo lifts in early September, handing operators a clear runway to update while details stay out of reach.
AI-generated reports complicate triage across Bitcoin infrastructure
The Core Lightning warning lands during a broader run of Bitcoin infrastructure failures. A 2021 Coldcard firmware bug that routed seed generation to a weak software randomizer has drained roughly $114 million in BTC since July 30 across more than 5,200 addresses. On Aug. 3, swap bridge Boltz halted its service indefinitely, saying "attackers now iterate faster than a team our size can find and patch." Four days later, BTCPay Server told merchants to update to 2.4.2 or shut down over an actively exploited flaw.
The Bitcoin Red Team, a volunteer group running AI-assisted audits across Bitcoin's open-source stack since the Coldcard exploit, said on Aug. 5 that 16 researchers had filed 4,962 findings across 390 projects in 27.5 hours, including 85 critical and 635 high-severity issues. Core Lightning attributed the reports it is triaging to "multiple sources" without naming the Red Team.
Two-week embargo leaves operators with a single action
Neither the patched binaries nor a formal advisory had appeared as of Wednesday afternoon. The most recent tagged release on the Core Lightning repository is v26.06.6, published July 22. The project's GitHub security advisories page lists none, and neither the Core Lightning account nor Blockstream has posted about it.
The guidance conditions the shutdown on declining to upgrade — an upgrade that is not yet downloadable. Older releases, including version 26.04, will not receive support during the security response, effectively pushing everyone toward the newest builds. The scheduled 26.09 release remains planned for late September.
The newly confirmed problems are separate from denial-of-service vulnerabilities disclosed earlier this year that could remotely crash Core Lightning nodes. Two related flaws involved memory exhaustion inside the connectd and gossipd daemons, both patched before the latest warning.
Bitcoin traded at $78,490 on Wednesday afternoon, down 0.5 percent over 24 hours and up about 15 percent on the week, per CoinGecko, showing no reaction to the security alert. The capacity decline and the security scramble together raise questions about Lightning's reliability as a scaling layer, even with no confirmed fund losses tied to the current flaws.
This article is for informational purposes only and does not constitute investment advice.