Core Lightning maintainers have warned users of Blockstream’s CLN implementation to take nodes offline after several vulnerabilities were disclosed through AI-based CVE reports. The team said an emergency fix is being prepared and advised operators to wait for signed binaries before bringing systems back into normal operation.

The developers said they are aiming to release the fix within 48 hours and plan full public disclosure within two weeks. At the time of the warning, maintainers said they had no reports of fund losses or active exploitation, but described at least one of the issues as severe enough to justify shutting nodes down immediately.

Emergency warning for CLN operators

The alert was issued on Wednesday by the Core Lightning maintainers, who said multiple flaws had been identified in Core Lightning, also known as CLN. The software is Blockstream’s implementation of the Lightning Network, the Bitcoin second-layer system designed for off-chain payments.

According to the notice, node operators should stop running current versions and prepare to install an updated release once it becomes available. The team also encouraged users to spread the warning to other operators, reflecting the urgency of the situation.

Fix targeted within 48 hours

Maintainers said they are preparing signed binaries for an emergency update and expect to have a fix ready within 48 hours. Until then, they advised users not only to upgrade when the patch is released but also to consider restarting nodes in an offline state so they no longer communicate with peers.

The team’s timeline includes a fuller disclosure within two weeks. That staggered approach suggests developers are prioritizing mitigation first, while delaying technical details until users have had time to apply the patch.

AI-based CVE reports exposed the flaws

The vulnerabilities were described as having been disclosed through AI-based CVE reports. The source report framed this as part of a broader shift in software security, where automated and AI-assisted tools are increasingly involved in identifying weaknesses that may previously have gone unnoticed for longer periods.

Even so, the maintainers stressed that, at the time of the warning, they had not seen signs of active exploitation and had received no reports of lost funds. Their recommendation to go offline was therefore presented as a precautionary measure in response to the seriousness of the bugs rather than evidence that attacks were already under way.

Wider Lightning backdrop

The warning lands against a mixed backdrop for the Lightning Network. As a second-layer system for Bitcoin, Lightning handles transactions off-chain, while actions such as topping up, opening channels, and closing channels still rely on on-chain settlement.

At the time referenced in the report, Lightning Network capacity stood at 3,998 BTC, roughly $313.5 million. The same report said capacity had been trending down since May 30 and had declined overall since December 27, 2025.

What comes next

The next confirmed step is the release of signed binaries for the emergency update. Core Lightning users have been told to keep current versions offline and then install the fix once it is published.

After that, the maintainers said they expect to provide full disclosure within two weeks, which should clarify the scope of the vulnerabilities and the exact remediation required. Until then, the only confirmed guidance is to shut down affected CLN nodes and wait for the official patched release.

Source: news.bitcoin.com