Bitcoin Lightning Network implementation Core Lightning has confirmed multiple security vulnerabilities and urged node operators to install an upcoming security update.
The project said several flaws were discovered while reviewing a large volume of AI-generated CVE reports, though it has not yet disclosed their technical details, severity or CVE identifiers. No related exploits or financial losses have been reported.
Core Lightning said upgrading is the primary recommendation. Operators unable to upgrade immediately can restart their nodes with the --offline option, which blocks incoming, outgoing and routed payments while keeping the daemon running.
Keeping the software active allows nodes to continue monitoring the Bitcoin blockchain and respond if a counterparty force-closes a Lightning channel.
The newly confirmed vulnerabilities are separate from remote denial-of-service flaws disclosed in May and July, which were already patched in previous releases.
The project said several flaws were discovered while reviewing a large volume of AI-generated CVE reports, though it has not yet disclosed their technical details, severity or CVE identifiers. No related exploits or financial losses have been reported.
Core Lightning said upgrading is the primary recommendation. Operators unable to upgrade immediately can restart their nodes with the --offline option, which blocks incoming, outgoing and routed payments while keeping the daemon running.
Keeping the software active allows nodes to continue monitoring the Bitcoin blockchain and respond if a counterparty force-closes a Lightning channel.
The newly confirmed vulnerabilities are separate from remote denial-of-service flaws disclosed in May and July, which were already patched in previous releases.
