Core Lightning Tells Operators to Take Nodes Offline Before Unreleased Fix Goes Public

Core Lightning Tells Operators to Take Nodes Offline Before Unreleased Fix Goes Public

N
News Editor
2026-08-26 20:07:46
Core Lightning maintainers have told node operators to take their nodes offline unless they upgrade to a release that had not been published as of Wednesday afternoon, leaving users of one of Bitcoin’s main Lightning implementations with little they can do beyond shutting down and waiting. The warning circulated first in the Core Lightning Discord and later spread through stacker.news and X, where Bitcoin Core contributor Mark Erhardt, known as Murch, said he had confirmed the message with a CLN maintainer and urged operators to act. The team said binaries containing fixes for multiple reported vulnerabilities would be published under a two-week embargo, with signatures to verify reproducibility, but no binaries or advisory had appeared by the time of publication. Core Lightning’s latest tagged release remains v26.06.6 from July 22, and its GitHub security advisories page listed nothing. The notice lands during a tense stretch for Bitcoin infrastructure. Over the past four weeks, the ecosystem has also seen the Coldcard firmware bug fallout, Boltz suspending service, and BTCPay Server warning merchants to update or shut down because of an actively exploited flaw. Despite the security concerns, Bitcoin traded at $78,490 on Wednesday afternoon, down 0.5% over 24 hours and up about 15% over the week, according to CoinGecko.

Core Lightning maintainers told node operators to take their nodes offline unless they upgrade to a release that had not been published as of Wednesday afternoon. For operators running one of Bitcoin’s main Lightning implementations, that left only one practical move: shut the node down, with no public explanation of the threat they were being asked to defend against.

Core Lightning, maintained by Blockstream with outside contributors, accounts for part of a network carrying 375,019,291,916 sats, or about 3,750 BTC, across 33,101 channels and 16,420 nodes, according to a mempool.space snapshot dated Aug. 20.

Operators were told to go offline if they do not upgrade

The guidance appeared in a message circulated in the Core Lightning Discord and reposted on Wednesday to stacker.news by an anonymous user. Instead of shipping the point release it had promised earlier this month, the team said it would publish binaries that contain fixes for many of the reported vulnerabilities while withholding details of what those fixes address.

「The details of the release will remain under embargo for two weeks,」 the message said. 「The binaries will be accompanied by the team’s signatures confirming reproducibility.」

It added: 「If you choose not to upgrade, we recommend taking your node --offline. Given the known risks, we will not support previous releases, including 26.04.」 The same message said the scheduled 26.09 release is still planned for late September.

No binaries and no advisory had appeared

As of Wednesday afternoon, neither the binaries nor a security advisory had been published. The most recent tagged release in the Core Lightning repository is v26.06.6, published on July 22. The project’s GitHub security advisories page listed no entries.

Neither the Core Lightning account nor Blockstream had posted publicly about the warning. On Wednesday, Blockstream’s feed instead carried a post-quantum signatures research report and a bitcoin-buying clip from chief executive Adam Back.

That pushed the warning through third parties. Mark Erhardt, a Bitcoin Core contributor at Localhost Research who is known as Murch, wrote on stacker.news that he had confirmed the message came from a moderator in the CLN Discord. About an hour later, he followed up: 「Got a confirmation from one of the CLN maintainers that this is legit, and you should take action.」

Erhardt also wrote on X that a 「severe」 issue had been found and that operators should consider restarting with --offline while watching for the point release.

Calle’s post gave the alert a wider audience

The message reached a broader audience after Calle, the pseudonymous developer behind the Cashu ecash protocol, amplified it at 2:41 p.m. ET with more forceful wording than the original CLN text.

He wrote: 「URGENT: Critical vulnerability in Core Lightning. Blockstream developers urge users to shut down CLN Lightning nodes right NOW!」 He then posted instructions for restarting with the --offline flag.

The original CLN message does not use the word critical, does not describe a single vulnerability, and does not tell operators to shut down immediately. It makes the shutdown recommendation conditional on not upgrading, even though that upgrade was not yet available for download.

Calle also helps run Bitcoin Red Team, a volunteer group that has been carrying out AI-assisted audits across Bitcoin’s open-source stack since the Coldcard exploit. On Aug. 5, he said 16 researchers had filed 4,962 findings across 390 projects in 27.5 hours, including 85 critical and 635 high-severity issues. Core Lightning has said only that the reports it is triaging came from 「multiple sources,」 without naming Red Team.

CLN had already said it was handling AI-generated CVE reports

Core Lightning first addressed the pressure publicly on Aug. 13 in a post from its own account, language that later reappeared verbatim in the Discord message.

The team wrote: 「Like many open source Bitcoin projects, CLN has received a number of AI-generated CVE reports from multiple sources over the past 10 days. Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports and develop fixes where needed.」

At the time, the team said it was aiming to ship a point release 「within the next few days.」 Thirteen days later, the plan had shifted to publishing binaries under embargo.

Fourth Bitcoin infrastructure warning in four weeks

The shutdown notice marks a fourth incident in a string of Bitcoin infrastructure failures that began in late July.

One case involved a 2021 Coldcard firmware bug that routed seed generation to a weak software randomizer. Since July 30, that flaw has drained roughly $114 million in BTC across more than 5,200 addresses, with victims describing the loss of life savings.

On Aug. 3, swap bridge Boltz halted service indefinitely, saying 「attackers now iterate faster than a team our size can find and patch.」 Four days later, BTCPay Server told merchants to update to 2.4.2 or shut down because of an actively exploited flaw. Lightning nodes were swept overnight, including one operated by hardware wallet maker Foundation.

BTCPay maintainer Nicolas Dorier said that flaw was caught by Sparrow Wallet developer Craig Raw after he reviewed logs following his own loss of funds, and that Red Team’s scans had missed it.

Bitcoin price showed no visible reaction

Bitcoin traded at $78,490 on Wednesday afternoon, down 0.5% over 24 hours and up about 15% on the week, according to CoinGecko. The price action showed no visible reaction to the warning.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
70

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.