SECURITY

Core Lightning confirms multiple vulnerabilities, asks node operators to upgrade

Aug 28, 2026 · SECURITY

Core Lightning, the open-source implementation of Bitcoin's Lightning Network, confirmed multiple real vulnerabilities and asked node operators to install a forthcoming security update.

The project said it had assessed a large number of AI-generated CVE reports and found that several of them are real. It told operators not to shut down their nodes completely, but to restart them with --offline, which prevents payments from entering, leaving or routing through the node. Upgrading remains the primary option; --offline is the alternative for operators who have not yet updated.

Core Lightning noted that keeping the daemon active lets it follow the Bitcoin blockchain and respond if a counterparty force-closes a channel, which a fully stopped node cannot do. Operators using --offline were instructed to remove it after upgrading, or their nodes will remain disconnected.

The project has not published CVE identifiers or disclosed the nature or severity of the flaws. No exploitation or losses have been reported at the time of writing. The newly confirmed issues are separate from the remote denial-of-service vulnerabilities disclosed in May and July, which were patched in earlier releases.

Core Lightning advisory; Cointelegraph, Aug 27, 2026

Content on this page is for informational purposes only and is not financial advice.