EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

AI discovers key vulnerabilities in Bitcoin Lightning network, developers warn urgently

2026-08-28 00:41:41
Bookmark

Core Lightning warns node operators

Developers of Bitcoin payment software Core Lightning posted a warning on social media on Wednesday that multiple vulnerabilities marked in a batch of AI-generated security reports do exist and the development team is coordinating fixes. The project requires node operators to install and verify upcoming updates as soon as possible-if upgrades cannot be made, to run nodes in offline mode, rather than shutting down nodes directly leaving payment channels unmonitored.

"Offline flags block Peering Connection, so no payments will be routed in and out through your node," Core Lightning wrote,"But the node is still running, which means it continues to monitor the blockchain and take action when counterparties force the channel to close. Shutting down won't do this, so shutting down is a worse option."

Software developed by Core Lightning is used to send and route Bitcoin payments on the Lightning Network, which serves as a layer 2 network to accelerate transactions. Its team said it spent weeks reviewing a large number of AI-generated CVE reports (i.e. submissions describing potential software vulnerabilities).

The project has not disclosed how many vulnerabilities have been identified, what attackers may have used them to do, and whether anyone has actually used them. The project party stated that details will not be disclosed for at least two weeks while the development team prepares the fix and the operator updates the node.

"When the release arrives, please verify the signature and install it, and complete it as soon as possible, rather than delay it," Core Lightning said in a subsequent post.

In a separate post on the Core Lightning Discord server, the project said its "small team and external contributors" spent 10 days reviewing AI-generated vulnerability reports from multiple sources and developing fixes. The project initially planned to release a minor version within a few days, but later decided to distribute a signature reproducible build while keeping the details secret for two weeks, and strongly urged operators to upgrade during this period.

Core Lightning told operators that failed to upgrade in time to restart nodes using the--offline parameter, which would prevent payments and connections to other lightning nodes, while the software continued to monitor Bitcoin. The project said it will no longer support earlier versions, including 26.04, while version 26.09 is still scheduled to be released at the end of September.

Monitoring is necessary because lightning channels process payments outside the Bitcoin blockchain and settle on Bitcoin when closed. The node's background software runs and can respond when a counterparty forces a channel to close. "This is why we recommend going offline rather than shutting down: a running daemon will still track the chain and react when the adversary forces a shutdown, which shutdown nodes cannot," Core Lightning wrote on X.

AI-assisted safety review raises concerns

This warning follows other cases where Bitcoin companies and developers believe AI has discovered security holes in the ecosystem. In July, hardware wallet maker Coinkite said it believed attackers used AI to examine old software code and discovered weaknesses in the Coldcard wallet seed generation process. Wallet seeds are secret information that controls funds, and the vulnerability is linked to millions of dollars in stolen Bitcoin. Earlier this month, Bitcoin exchange service provider Boltz suspended its service, saying attackers were discovering the vulnerability faster than developers could fix it.

According to the Bitcoin Red Team, a volunteer group of cybersecurity and blockchain experts, AI-assisted review has so far produced 4962 possible findings in 390 Bitcoin projects. Initial assessments identified 85 as critical vulnerabilities and 635 as high severity, while admitting that some of them may be false positives.

Calle, a pseudonym Bitcoin developer and a member of the Bitcoin Red Team, said the group was trying to discover the vulnerability before the attackers did. "Right now, it's just a matter of time," Calle said."The reason Bitcoin Red Team exists now is that we need to get ahead of the attackers as quickly as possible." Calle, who also maintains the Cashu digital cash protocol, says AI makes it easier for people without security training to exploit software vulnerabilities. "Simple vulnerabilities can now be completed end-to-end by someone who doesn't know how to exploit them, without the help of AI."

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP