Core Lightning developers have issued an urgent security alert to Lightning Network node operators after AI-generated vulnerability reports uncovered several legitimate flaws. The team plans to keep technical details private for two weeks while fixes are prepared and distributed to operators.
Core Lightning, also known as CLN, is advising operators not to shut down their machines. Those unable to upgrade immediately should restart their nodes using the --offline option. This disables communication with other Lightning nodes while allowing the software to remain active.
The Lightning Network is built on Bitcoin and allows users to make faster, cheaper BTC payments without recording every transaction individually on the main blockchain. Core Lightning is one of the major implementations used to run nodes that process and route Lightning payments.
According to CLN developers, the team started receiving a high volume of vulnerability reports produced by AI models in early August. These reports identify potential security weaknesses, which developers then need to test to determine whether they represent genuine threats.
Several of the reported issues were confirmed to be real, according to the team. Developers are maintaining a two-week disclosure delay while they prepare patched versions, giving node operators time to update their software before the vulnerabilities are publicly detailed.
Why Lightning Nodes Should Remain Online
CLN’s warning spread across Bitcoin social media on Thursday, although some of the instructions were later misunderstood. The initial guidance told operators who could not upgrade immediately to restart their nodes with --offline rather than turning off their machines.
Developers subsequently clarified that operators should avoid powering down their nodes entirely. A node that is offline cannot monitor its Lightning payment channels, potentially leaving funds exposed.
Lightning payment channels allow two parties to lock BTC into a shared arrangement and repeatedly update their respective balances. When the channel closes, the final balance can be settled on the Bitcoin blockchain.
A Lightning node needs to monitor the Bitcoin blockchain for attempts to close a channel using an outdated balance. If such an attempt occurs, the node can respond onchain to protect its funds.
A completely powered-down machine cannot perform that monitoring or react to a malicious channel closure.
Using CLN’s --offline mode works differently. The setting disconnects the node from other Lightning participants, meaning it cannot send, receive or route payments. However, the software continues running and can still monitor Bitcoin for activity affecting its channels.
Core Lightning intends to release signed patched versions before publishing the full technical details. Signed releases will allow operators to verify that the software originated from the development team before installing it.
The project has not disclosed the number of vulnerabilities involved, what an attacker could potentially accomplish or whether any of the flaws have already been exploited. The planned Core Lightning 26.09 release is still scheduled for late September.
Second Lightning Security Alert This Month
The incident represents the second major Lightning security emergency reported in August.
Earlier this month, a vulnerability in BTCPay Server exposed credentials associated with Lightning nodes. Attackers reportedly used the flaw to drain funds from some affected nodes before developers released a fix. BTCPay developers later said AI was changing the balance between attackers and defenders and paid rewards to researchers who discovered the vulnerability.
AI has also been used more broadly to search Bitcoin software for potential security weaknesses. In late July, the Bitcoin Red Team, made up of 16 developers, scanned 390 Bitcoin repositories using AI models. The effort generated almost 5,000 findings, including 85 categorized as critical, in approximately 27 hours.
Meanwhile, a group including Coinbase, Block, BitGo, Blockstream and the Bitcoin Policy Institute called on AI companies in August to provide Bitcoin developers with early access to their most advanced models. The group argued that Bitcoin’s defenders should have access to the same powerful AI tools that potential attackers may already be using.

































