Core Lightning confirms the real security flaws in AI-generated vulnerability reports and recommends that nodes stay online.
The Core Lightning team said in an official post on August 14 that it has received a large number of AI-generated vulnerability reports in the past ten days, and it has been confirmed that there are real security flaws in them. The team advised node operators not to shut down nodes until the repair solution was ready, but to restart them in offline mode.
Like many open source Bitcoin projects, CLN has received multiple AI-generated CVE reports from different sources in the past 10 days. Our small team, along with several valuable open source contributors, has been intensively verifying and classifying these reports...

Instead, the team's official guidance is to restart nodes using offline flags. This setting prevents payment routing in, out of, or through nodes, but keeps the daemon running so that it can still monitor on-chain activity and react when a channel partner forces a shutdown. Nodes with complete power outages cannot do this. On Umbrel and Start9 platforms, offline mode is a startup setting rather than a dashboard switch, which operators on these platforms need to set before restarting.
There is a two-week confidentiality period before public repairs
Core Lightning plans to release signature binaries in the next few days. Full technical details, including which CVE's are real, will be kept secret for two weeks after release to prevent attackers from reverse-engineering the vulnerability before most operators complete patching. All previous versions, including 26.04, are no longer supported. The team said its version originally planned for release on 26.09 is still scheduled to be launched in late September.
Core Lightning has been classifying a large number of AI-generated CVE reports in recent weeks. Several of them are authentic and are being repaired in a coordinated manner.
What to do now: Don't shut down your node. Restart using the--offline flag.
This flag disconnects the Peering Connection, so no payment routes will come in...

As of this writing, Core Lightning has not reported any confirmed exploits or financial losses related to these specific vulnerabilities. According to its GitHub repository, the current stable version of the project is v26.06.6. Suspension of operations rather than pushing unverified fixes is not unique to Core Lightning;MANTRA suspended its network immediately after confirming earlier this year that attackers exploited upstream vulnerabilities, rather than letting the chain continue to run while the scope of the vulnerability was unclear.
Why choose to go offline instead of shutting down: BTCPay Server's recent capital loss incident
The difference between offline and shutdown is not routine caution. On August 7, BTCPay Server disclosed a serious vulnerability that had been actively exploited in its security bulletin, urging users to update to version 2.4.2 or shut down the system. Hardware wallet maker Foundation and Bitcoin publication Citadel21 both confirmed that their lightning nodes were cleared during that incident. BTCPay founder Nicolas Dorier said the vulnerability was discovered only after the developer personally lost money and traced it back to it, rather than through any automatic scanning.
Core Lightning's own reason for choosing to go offline is that nodes continue to monitor chain activity and respond to forced shutdowns-just solves the failure mode that operators encountered three weeks ago: nodes that are completely down cannot defend against opponents trying to force a channel closure. Although Core Lightning does not name BTCPay Server, the guide reads like a team observing what happened on adjacent projects and adjusting its recommendations accordingly. Other events in the cryptocurrency space this year have documented the cost of misbehaving: BounceBit closed the bug after it exhausted a quarter of its circulation supply, a reminder of how quickly unpatched flaws can turn into irreparable damage once the bug is actively exploited.
Operators should pay attention to the official Core Lightning channel to obtain signature binaries, verify signatures before installation, and remove the--offline flag after the upgrade is complete.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC