EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Core Lightning urges node operators to upgrade after confirming security vulnerabilities

2026-08-28 00:43:52
Bookmark

Core Lightning confirms multiple security vulnerabilities, urges node operators to upgrade or run offline

Core Lightning has identified multiple security vulnerabilities in its Bitcoin Lightning Network software and urged node operators to install upcoming security updates or temporarily run nodes offline.

Overview

Core Lightning identified multiple vulnerabilities after reviewing a large number of AI-generated CVE reports. Node operators are urged to install security updates, while offline mode is used as a temporary option while waiting for upgrades. Running offline nodes stop lightning payments and routing, while allowing daemons to continue monitoring the Bitcoin blockchain. Core Lightning has not disclosed the severity of these vulnerabilities, CVE identifiers, or any evidence of exploitation or related damage.

Incident Details

Core Lightning said on Thursday that its developers have been reviewing a large number of AI-generated generic vulnerability and exposure reports and confirmed that several of the submitted reports point to real issues that need to be fixed. The project recommends that operators prioritize upgrades. Operators that have not yet installed security updates can use the--offline option to restart Core Lightning, which will prevent nodes from connecting to peers and prevent payments from entering, leaving, or routing through the node. Core Lightning initially described offline settings as a protective measure during fix preparation, but later clarified that operators should prioritize upgrades once patch software is available.

Technical details of the newly confirmed vulnerability have not been made public. Core Lightning did not disclose its severity, assign public CVE identifiers, and did not report evidence that attackers exploited these vulnerabilities. Core Lightning nodes can remain active without routing payments. Using the--offline setting allows the Core Lightning daemon to remain active while disconnecting nodes from the Lightning network. In this configuration, nodes do not accept incoming Peering Connection and do not attempt to reconnect existing peer nodes. As a result, while the operator waits to install security updates, payments cannot be made through the affected nodes. Core Lightning said operators should not simply stop software because active daemons can continue to track the Bitcoin blockchain and respond when another party forces the lightning channel to be closed. A node that is completely stopped cannot perform the same monitoring while offline. When the channel is closed, channel counterparties can post transactions on Bitcoin, so continuous monitoring of the blockchain is part of normal lightning node operations.

Post-upgrade considerations

Once operators install the patch version, Core Lightning said they should remove the offline option before normal restarts. Maintaining this setting after an upgrade disconnects nodes from peers and prevents them from sending, receiving, or routing lightning payments. This recommendation applies during the period when developers deal with issues identified during AI-generated vulnerability submission reviews. Core Lightning has not publicly stated which components are affected or what conditions are required to exploit identified vulnerabilities. The project also did not disclose whether all supported software versions were affected, leaving operators to rely on upgrade instructions that accompany security updates.

The new vulnerability and previous DoS fixes

The newly identified issue is separate from a denial of service vulnerability disclosed earlier this year that could remotely crash Core Lightning nodes. Two related vulnerabilities involve memory exhaustion within different daemons of Core Lightning. One affects connectd (the component that handles Peering Connection), and the other affects Gossipd (handles network information used by Lightning nodes). In the connectd case, a remote peer node can trigger unlimited memory usage, which ultimately leads to a memory exhaustion crash. The issue was fixed before the latest vulnerability warning was released. Another vulnerability allows remote peers to flood Gossipd with channel update messages, causing internal mappings for unknown short channel IDs to continue to consume memory until the machine becomes unresponsive or crashes. Both issues rely on resource exhaustion, and Core Lightning has not said whether the newly confirmed vulnerability involves similar components or attack methods.

Other security fixes in Bitcoin infrastructure

This year, security fixes have also emerged in other parts of Bitcoin's infrastructure that require node operators to install updated software. In May, Bitcoin Core disclosed a vulnerability that could allow miners to remotely crash vulnerable nodes. The issue was traced as CVE-2024-52911, affecting Bitcoin Core versions after version 0.14.0 and before version 29.0. Developers have fixed the issue in Bitcoin Core 29.0 released in April 2025, and later publicly disclosed it in May 2026. The vulnerability involves Bitcoin Core's script interpreter during block verification. A specially crafted invalid block can cause a node to access data after the associated memory is freed, potentially causing software to crash. Bitcoin Core stated that remote code execution is possible, but it is unlikely due to block data limitations.

Continuous patching work for Bitcoin software projects

In June, another Bitcoin Core privacy vulnerability was resolved with a 31.1rc1 candidate, involving changes to blockchain verification, wallet, network and MuSig2 security. The privacy issue affects the PrivateBroadcast feature, which is designed to reduce the amount of information exposed when a transaction is first transmitted. Developers released fixes ahead of the release of the next stable version of Bitcoin Core and asked users to test candidate versions before production deployment. Lightning Network Implementation has also encountered specific software problems before. In June 2023, operators implemented by Lightning Labs LND were warned not to upgrade to version 0.16.3 due to memory leaks. This issue causes software memory usage to increase over time, which may eventually crash the node. At the time, operators that had installed LND 0.16.3 were advised to downgrade to version 0.16.2 while developers addressed the issue.

Another Lightning cybersecurity issue emerged later in 2023, with developer Antoine Riard describing an alternative cyclic attack that could be used to attack Lightning payment channels. Riard subsequently withdrew from Lightning Network development, arguing that the issue required changes beyond short-term mitigation measures. Riard said at the time that no actual replacement loop attacks had been observed or reported in the previous 10 months, but there was a functional test to test the affected lightning channel in the Bitcoin Core memory pool. The vulnerability involves replacing unconfirmed transactions under certain conditions, which could interfere with the transaction sequence used to protect funds in the lightning channel. Riard said existing mitigations could make the attack more difficult to implement, but he did not see it as a permanent solution.

Core Lightning retains the latest vulnerability details

For current Core Lightning vulnerabilities, operators have received protection instructions before the technical details of the underlying vulnerability are disclosed. The project said several AI-generated CVE reports were valid, but the affected functions, attack paths, or conditions needed to replicate the problem have not been announced. Based on Core Lightning's disclosures to date, no losses or successful attacks have been reported related to these newly confirmed vulnerabilities. Operators that have not yet upgraded are instructed to use the-offline option and keep the daemon running, allowing the software to continue tracking channel-related transactions on Bitcoin without participating in flash payments. After installing the security update, Core Lightning stated that operators using temporary configurations must remove-offline to reconnect nodes to peers and resume normal payment and routing activities.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP