Core Lightning maintainers told node operators to take their nodes offline unless they upgrade to a release that had not been published as of Wednesday afternoon. For operators running one of Bitcoin’s main Lightning implementations, that left only one practical move: shut the node down, with no public explanation of the threat they were being asked to defend against.
Core Lightning, maintained by Blockstream with outside contributors, accounts for part of a network carrying 375,019,291,916 sats, or about 3,750 BTC, across 33,101 channels and 16,420 nodes, according to a mempool.space snapshot dated Aug. 20.
Operators were told to go offline if they do not upgrade
The guidance appeared in a message circulated in the Core Lightning Discord and reposted on Wednesday to stacker.news by an anonymous user. Instead of shipping the point release it had promised earlier this month, the team said it would publish binaries that contain fixes for many of the reported vulnerabilities while withholding details of what those fixes address.
「The details of the release will remain under embargo for two weeks,」 the message said. 「The binaries will be accompanied by the team’s signatures confirming reproducibility.」
It added: 「If you choose not to upgrade, we recommend taking your node --offline. Given the known risks, we will not support previous releases, including 26.04.」 The same message said the scheduled 26.09 release is still planned for late September.
No binaries and no advisory had appeared
As of Wednesday afternoon, neither the binaries nor a security advisory had been published. The most recent tagged release in the Core Lightning repository is v26.06.6, published on July 22. The project’s GitHub security advisories page listed no entries.
Neither the Core Lightning account nor Blockstream had posted publicly about the warning. On Wednesday, Blockstream’s feed instead carried a post-quantum signatures research report and a bitcoin-buying clip from chief executive Adam Back.
That pushed the warning through third parties. Mark Erhardt, a Bitcoin Core contributor at Localhost Research who is known as Murch, wrote on stacker.news that he had confirmed the message came from a moderator in the CLN Discord. About an hour later, he followed up: 「Got a confirmation from one of the CLN maintainers that this is legit, and you should take action.」
Erhardt also wrote on X that a 「severe」 issue had been found and that operators should consider restarting with --offline while watching for the point release.
Calle’s post gave the alert a wider audience
The message reached a broader audience after Calle, the pseudonymous developer behind the Cashu ecash protocol, amplified it at 2:41 p.m. ET with more forceful wording than the original CLN text.
He wrote: 「URGENT: Critical vulnerability in Core Lightning. Blockstream developers urge users to shut down CLN Lightning nodes right NOW!」 He then posted instructions for restarting with the --offline flag.
The original CLN message does not use the word critical, does not describe a single vulnerability, and does not tell operators to shut down immediately. It makes the shutdown recommendation conditional on not upgrading, even though that upgrade was not yet available for download.
Calle also helps run Bitcoin Red Team, a volunteer group that has been carrying out AI-assisted audits across Bitcoin’s open-source stack since the Coldcard exploit. On Aug. 5, he said 16 researchers had filed 4,962 findings across 390 projects in 27.5 hours, including 85 critical and 635 high-severity issues. Core Lightning has said only that the reports it is triaging came from 「multiple sources,」 without naming Red Team.
CLN had already said it was handling AI-generated CVE reports
Core Lightning first addressed the pressure publicly on Aug. 13 in a post from its own account, language that later reappeared verbatim in the Discord message.
The team wrote: 「Like many open source Bitcoin projects, CLN has received a number of AI-generated CVE reports from multiple sources over the past 10 days. Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports and develop fixes where needed.」
At the time, the team said it was aiming to ship a point release 「within the next few days.」 Thirteen days later, the plan had shifted to publishing binaries under embargo.
Fourth Bitcoin infrastructure warning in four weeks
The shutdown notice marks a fourth incident in a string of Bitcoin infrastructure failures that began in late July.
One case involved a 2021 Coldcard firmware bug that routed seed generation to a weak software randomizer. Since July 30, that flaw has drained roughly $114 million in BTC across more than 5,200 addresses, with victims describing the loss of life savings.
On Aug. 3, swap bridge Boltz halted service indefinitely, saying 「attackers now iterate faster than a team our size can find and patch.」 Four days later, BTCPay Server told merchants to update to 2.4.2 or shut down because of an actively exploited flaw. Lightning nodes were swept overnight, including one operated by hardware wallet maker Foundation.
BTCPay maintainer Nicolas Dorier said that flaw was caught by Sparrow Wallet developer Craig Raw after he reviewed logs following his own loss of funds, and that Red Team’s scans had missed it.
Bitcoin price showed no visible reaction
Bitcoin traded at $78,490 on Wednesday afternoon, down 0.5% over 24 hours and up about 15% on the week, according to CoinGecko. The price action showed no visible reaction to the warning.

