Core Lightning, one of the main client implementations of Bitcoin’s Lightning Network, has told node operators to prepare an emergency upgrade or take their nodes offline after a wave of artificial-intelligence-generated vulnerability reports. The alert, reported by The Defiant , puts operators in an awkward spot: the patched binaries have not been published, and the fixes sit behind a two-week disclosure embargo.
Operators asked to upgrade or disconnect
Guidance circulated in the Core Lightning Discord and confirmed by a maintainer gave node runners a stark choice. “If you choose not to upgrade, we recommend taking your node –offline,” the message said, adding that “given the known risks, we will not support previous releases, including 26.04.” The team said the details of the release will remain under embargo for two weeks and that binaries will ship with signatures confirming reproducibility, while a scheduled 26.09 release stays planned for late September.
AI-generated reports trigger the response
The team first flagged the pressure on Aug. 13, writing on X that Core Lightning had “received a number of AI-generated CVE reports from multiple sources over the past 10 days” and was triaging them with outside contributors. That follows a surge of AI-assisted audits across Bitcoin’s open-source stack, including the volunteer Bitcoin Red Team, which recently filed thousands of findings across hundreds of projects. Core Lightning is maintained by Blockstream.
A wider run of infrastructure alarms
The warning covers a network carrying roughly 3,750 BTC across more than 33,000 channels, according to mempool.space data cited in the report. It is the fourth security scare for Bitcoin infrastructure in about four weeks, following the Coldcard firmware losses and a BTCPay Server update warning, and it echoes earlier Lightning Network vulnerabilities that pushed users to upgrade. Operators who keep channels open on an unpatched node would face forced-closure or fund risk if an exploit drops, while payments routed through affected channels could see liquidity disruptions. Because the embargoed fixes still have no public description, operators cannot yet judge how serious the risk to their funds actually is.