Core Lightning confirms multiple security vulnerabilities, urges node operators to upgrade or run offline
Core Lightning has identified multiple security vulnerabilities in its Bitcoin Lightning Network software and urged node operators to install upcoming security updates or temporarily run nodes offline.
Overview
Core Lightning identified multiple vulnerabilities after reviewing a large number of AI-generated CVE reports. Node operators are urged to install security updates, while offline mode is used as a temporary option while waiting for upgrades. Running offline nodes stop lightning payments and routing, while allowing daemons to continue monitoring the Bitcoin blockchain. Core Lightning has not disclosed the severity of these vulnerabilities, CVE identifiers, or any evidence of exploitation or related damage.
Incident Details
Core Lightning said on Thursday that its developers have been reviewing a large number of AI-generated generic vulnerability and exposure reports and confirmed that several of the submitted reports point to real issues that need to be fixed. The project recommends that operators prioritize upgrades. Operators that have not yet installed security updates can use the--offline option to restart Core Lightning, which will prevent nodes from connecting to peers and prevent payments from entering, leaving, or routing through the node. Core Lightning initially described offline settings as a protective measure during fix preparation, but later clarified that operators should prioritize upgrades once patch software is available.
Technical details of the newly confirmed vulnerability have not been made public. Core Lightning did not disclose its severity, assign public CVE identifiers, and did not report evidence that attackers exploited these vulnerabilities. Core Lightning nodes can remain active without routing payments. Using the--offline setting allows the Core Lightning daemon to remain active while disconnecting nodes from the Lightning network. In this configuration, nodes do not accept incoming Peering Connection and do not attempt to reconnect existing peer nodes. As a result, while the operator waits to install security updates, payments cannot be made through the affected nodes. Core Lightning said operators should not simply stop software because active daemons can continue to track the Bitcoin blockchain and respond when another party forces the lightning channel to be closed. A node that is completely stopped cannot perform the same monitoring while offline. When the channel is closed, channel counterparties can post transactions on Bitcoin, so continuous monitoring of the blockchain is part of normal lightning node operations.
Post-upgrade considerations
Once operators install the patch version, Core Lightning said they should remove the offline option before normal restarts. Maintaining this setting after an upgrade disconnects nodes from peers and prevents them from sending, receiving, or routing lightning payments. This recommendation applies during the period when developers deal with issues identified during AI-generated vulnerability submission reviews. Core Lightning has not publicly stated which components are affected or what conditions are required to exploit identified vulnerabilities. The project also did not disclose whether all supported software versions were affected, leaving operators to rely on upgrade instructions that accompany security updates.
The new vulnerability and previous DoS fixes
The newly identified issue is separate from a denial of service vulnerability disclosed earlier this year that could remotely crash Core Lightning nodes. Two related vulnerabilities involve memory exhaustion within different daemons of Core Lightning. One affects connectd (the component that handles Peering Connection), and the other affects Gossipd (handles network information used by Lightning nodes). In the connectd case, a remote peer node can trigger unlimited memory usage, which ultimately leads to a memory exhaustion crash. The issue was fixed before the latest vulnerability warning was released. Another vulnerability allows remote peers to flood Gossipd with channel update messages, causing internal mappings for unknown short channel IDs to continue to consume memory until the machine becomes unresponsive or crashes. Both issues rely on resource exhaustion, and Core Lightning has not said whether the newly confirmed vulnerability involves similar components or attack methods.
Other security fixes in Bitcoin infrastructure
This year, security fixes have also emerged in other parts of Bitcoin's infrastructure that require node operators to install updated software. In May, Bitcoin Core disclosed a vulnerability that could allow miners to remotely crash vulnerable nodes. The issue was traced as CVE-2024-52911, affecting Bitcoin Core versions after version 0.14.0 and before version 29.0. Developers have fixed the issue in Bitcoin Core 29.0 released in April 2025, and later publicly disclosed it in May 2026. The vulnerability involves Bitcoin Core's script interpreter during block verification. A specially crafted invalid block can cause a node to access data after the associated memory is freed, potentially causing software to crash. Bitcoin Core stated that remote code execution is possible, but it is unlikely due to block data limitations.
Continuous patching work for Bitcoin software projects
In June, another Bitcoin Core privacy vulnerability was resolved with a 31.1rc1 candidate, involving changes to blockchain verification, wallet, network and MuSig2 security. The privacy issue affects the PrivateBroadcast feature, which is designed to reduce the amount of information exposed when a transaction is first transmitted. Developers released fixes ahead of the release of the next stable version of Bitcoin Core and asked users to test candidate versions before production deployment. Lightning Network Implementation has also encountered specific software problems before. In June 2023, operators implemented by Lightning Labs LND were warned not to upgrade to version 0.16.3 due to memory leaks. This issue causes software memory usage to increase over time, which may eventually crash the node. At the time, operators that had installed LND 0.16.3 were advised to downgrade to version 0.16.2 while developers addressed the issue.
Another Lightning cybersecurity issue emerged later in 2023, with developer Antoine Riard describing an alternative cyclic attack that could be used to attack Lightning payment channels. Riard subsequently withdrew from Lightning Network development, arguing that the issue required changes beyond short-term mitigation measures. Riard said at the time that no actual replacement loop attacks had been observed or reported in the previous 10 months, but there was a functional test to test the affected lightning channel in the Bitcoin Core memory pool. The vulnerability involves replacing unconfirmed transactions under certain conditions, which could interfere with the transaction sequence used to protect funds in the lightning channel. Riard said existing mitigations could make the attack more difficult to implement, but he did not see it as a permanent solution.
Core Lightning retains the latest vulnerability details
For current Core Lightning vulnerabilities, operators have received protection instructions before the technical details of the underlying vulnerability are disclosed. The project said several AI-generated CVE reports were valid, but the affected functions, attack paths, or conditions needed to replicate the problem have not been announced. Based on Core Lightning's disclosures to date, no losses or successful attacks have been reported related to these newly confirmed vulnerabilities. Operators that have not yet upgraded are instructed to use the-offline option and keep the daemon running, allowing the software to continue tracking channel-related transactions on Bitcoin without participating in flash payments. After installing the security update, Core Lightning stated that operators using temporary configurations must remove-offline to reconnect nodes to peers and resume normal payment and routing activities.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC