Core Lightning has confirmed real security flaws among a wave of AI-generated vulnerability reports it received over the past ten days, and it is telling node operators not to shut their nodes down while a fix is prepared, according to the team’s official post on August 14.
Like many open source Bitcoin projects, CLN has received a number of AI-generated CVE reports from multiple sources over the past 10 days. Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports…
— Core Lightning ⚡️ (@Core_LN) August 13, 2026
Instead, the team’s official guidance is to restart with the offline flag. That setting blocks payments from routing in, out, or through the node, but keeps the daemon running so it can still watch the chain and react if a channel partner force-closes. A fully powered-off node cannot do that. On Umbrel and Start9, offline is a startup setting rather than a dashboard toggle, and operators on those platforms need to set it before restarting.
A two-week embargo before the fixes go public
Core Lightning plans to publish signed binaries within the next few days. Full technical details, including which CVEs were real, stay embargoed for two weeks after that, so attackers cannot reverse-engineer the flaws before most operators have patched. Every release before this one, including 26.04, is now unsupported. The team says its already-planned 26.09 release is still on track for late September.
Core Lightning has been triaging a high volume of AI-generated CVE reports over recent weeks. Several are real, and a coordinated fix is underway.
What to do now: do not shut your node down. Restart it with –offline.
That flag stops peer connections, so no payments route in,…
— Core Lightning ⚡️ (@Core_LN) August 26, 2026
As of this writing, Core Lightning has reported no confirmed exploitation or fund loss tied to these specific vulnerabilities. The project’s current stable release, per its GitHub repository, is v26.06.6. Pausing operations rather than pushing an unverified fix live is not unique to Core Lightning either; MANTRA halted its network earlier this year the moment it confirmed an attacker had exploited an upstream vulnerability, rather than let the chain keep running while the extent of the flaw was still unclear.
Why offline, not off: BTCPay Server’s recent drain
That distinction between offline and off is not routine caution. On August 7, BTCPay Server disclosed a critical bug in its own security advisory that was already being actively exploited, urging users to update to version 2.4.2 or shut down. Hardware wallet maker Foundation and Bitcoin publication Citadel21 both confirmed their Lightning nodes were swept during that incident. BTCPay founder Nicolas Dorier said the flaw was only caught after a developer personally lost funds tracing it, not by any automated scan.
Core Lightning’s own justification for offline, a node that keeps watching the chain and can still respond to a force-close, addresses exactly the failure mode operators hit three weeks earlier: a node that goes fully dark cannot defend a channel if a counterparty tries to force it closed. Core Lightning has not named BTCPay Server, but the guidance reads as a team that watched what happened to a neighboring project and adjusted its own advice accordingly. The stakes of getting that response wrong are already on record elsewhere in crypto this year: BounceBit’s own shutdown came only after an exploit had already drained a quarter of BB’s circulating supply, a reminder of how fast an unpatched flaw can turn into an unrecoverable loss once it is actively being used.
Operators should watch Core Lightning’s own channel for the signed binaries, verify signatures before installing, and remove the –offline flag once they have upgraded.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

















