
Core Lightning has officially confirmed multiple critical vulnerabilities affecting its Bitcoin Lightning Network implementation, with maintainers urging all node operators to take nodes offline immediately and stop communicating with the network. According to the latest disclosure, a signed emergency patch is expected within approximately 48 hours with full public disclosure scheduled for approximately two weeks. As of the disclosure, no confirmed fund losses or active exploitation have been reported, indicating the responsible-disclosure pipeline between the Bitcoin Red Team and CLN maintainers is functioning as intended. The vulnerabilities were discovered through an AI-assisted security audit by the Bitcoin Red Team, which ran an audit across 390+ open-source Bitcoin repositories, generating roughly 4,962 findings in approximately 27.5 hours using Kimi K3 from Moonshot AI as the primary model. BTCPay Server has paused CLN routes as a precautionary measure, heightening operational risk and potentially disrupting Lightning Network payment routing and liquidity in the near term.
Lightning moves small Bitcoin payments off the main blockchain through channels between nodes, creating significant exposure during this vulnerability period. Core Lightning has provided operators with two protective options: the main recommendation to take affected nodes offline immediately, or temporarily run nodes offline using the –offline configuration option. This offline setting prevents nodes from connecting to peers and stops payments from entering, leaving, or routing through affected nodes while allowing the Core Lightning daemon to remain active and continue monitoring the Bitcoin blockchain. The project emphasizes that operators should not simply stop the software entirely, as an active daemon can continue following the Bitcoin blockchain and respond if another party force-closes a Lightning channel. The current offline recommendation is more urgent than previous guidance, as a patch is not yet available for the disclosed vulnerability.
According to Core Lightning, withholding technical details is the strategy to prevent attackers from building working exploits within hours. The updates carry developer signatures confirming reproducibility, allowing outsiders to check that the release matches the source code. The fixes cover many of the reported flaws, though not every one, with the project not publicly describing which components are affected or what conditions would be needed to exploit the confirmed flaws. Once operators have installed the patched version, they should remove the –offline option before restarting normally, as leaving the setting enabled would keep the node disconnected from its peers and prevent normal Lightning payment activity. Core Lightning is working to release a patched version as soon as possible, with the current recommendation to take nodes offline until the update becomes available.
This vulnerability confirmation adds to ongoing Bitcoin infrastructure security challenges this year. The current disclosure represents the fourth major incident in a run of Bitcoin infrastructure failures that began in late July, following a 2021 Coldcard firmware bug that drained roughly $114 million in BTC since July 30 across more than 5,200 addresses, and BTCPay Server's active exploit that swept Lightning nodes overnight. Lightning Network public channel capacity has declined significantly since December 27, 2025, with the current figure showing material decline over roughly eight months. The CLN vulnerabilities emerged from the Bitcoin Red Team's AI-assisted security audit pipeline, demonstrating both the capability and urgency of AI-accelerated security auditing on open-source Bitcoin infrastructure. The reflexive response from rational node operators may reflect operational risk concerns rather than bearish sentiment on Bitcoin's price, with the headline potentially weighing on risk appetite around Bitcoin's scaling stack.