
Core Lightning developers have issued an urgent warning to Lightning Network node operators after AI-generated security reports exposed several legitimate vulnerabilities. The team is withholding technical information for two weeks to allow developers to prepare patches and give operators time to secure their nodes.
Core Lightning, or CLN, has specifically advised operators not to power down their machines. Those who cannot install an update immediately should restart their nodes with the --offline setting. This blocks connections with other Lightning nodes but keeps the software running.
The Lightning Network is a layer built on Bitcoin that enables users to send BTC quickly and at lower cost without recording every payment directly on the main blockchain. CLN is one of the leading software implementations used to operate Lightning nodes and route transactions.
According to Core Lightning developers, a surge of AI-generated vulnerability reports began arriving in early August. Developers reviewed the reports and tested the potential weaknesses to determine whether they could be exploited in practice.
Several vulnerabilities were confirmed as genuine. The development team is now using a two-week disclosure period to complete fixes and allow operators to upgrade their nodes before the technical details are released publicly.
Why Lightning Nodes Should Stay Online
The security warning spread through Bitcoin social media on Thursday, but the guidance was initially misunderstood in some posts. CLN’s original recommendation was that operators unable to update immediately should restart their nodes with --offline rather than shut down their machines.
Developers later clarified that completely turning off a Lightning node is not advisable. A powered-down node cannot monitor the Bitcoin blockchain or react if an issue arises with one of its payment channels.
Lightning channels allow participants to lock BTC together and repeatedly update balances without putting every transaction onchain. When a channel is closed, the final balance is recorded on Bitcoin.
Nodes need to continuously monitor the blockchain because a counterparty could attempt to close a channel using an older channel state. If that happens, an active node can respond onchain and protect its funds.
A fully powered-off machine cannot detect or respond to such an event.
By contrast, CLN’s --offline mode disconnects the node from other Lightning participants while leaving the software active. Payments cannot be sent, received or routed in this state, but the node can continue watching the Bitcoin blockchain.
Core Lightning plans to release signed versions of the patched software first. This will allow operators to confirm that the updates genuinely came from the development team before installing them.
The project has not revealed how many vulnerabilities were found, what attackers could potentially do with them or whether any have already been exploited. The regularly scheduled Core Lightning 26.09 release is still expected in late September.
Second Lightning Security Emergency This Month
The incident marks the second significant Lightning security emergency reported in August.
Earlier this month, a vulnerability in BTCPay Server exposed credentials used to control Lightning nodes. Attackers reportedly exploited the issue and drained funds from some affected nodes before a fix was released. BTCPay developers later said AI was changing the security balance between attackers and defenders and paid bounties to researchers who identified the vulnerability.
AI is also being used to identify weaknesses across Bitcoin software. In late July, the Bitcoin Red Team, a group of 16 developers, used AI models to examine 390 Bitcoin repositories. The review generated nearly 5,000 findings, including 85 classified as critical, in approximately 27 hours.
In a separate development, a group including Coinbase, Block, BitGo, Blockstream and the Bitcoin Policy Institute urged AI companies to provide Bitcoin developers with early access to their strongest models. The organizations argued that Bitcoin defenders should have access to advanced AI capabilities if attackers can already use similar tools.






