Core Lightning Tells Node Operators To Go Offline, With No Patch Published
Core Lightning's maintainers told node operators to take their nodes offline unless they upgrade to a release that has not been published yet.
That leaves operators of one of Bitcoin's main Lightning implementations with a single available action — shutting the node down — and no public description of what they are defending against. Core Lightning, maintained by Blockstream with outside contributors, runs a share of a network carrying 375,019,291,916 sats, or about 3,750 BTC, across 33,101 channels and 16,420 nodes as of the Aug. 20 snapshot, per mempool.space.
The guidance came in a message circulated in the Core Lightning Discord and reproduced on stacker.news on Wednesday by an anonymous poster. Rather than shipping the point release it promised earlier this month, the team said it will publish binaries carrying fixes for many of the reported vulnerabilities while holding back what they fix.
“The details of the release will remain under embargo for two weeks,” the message said. “The binaries will be accompanied by the team’s signatures confirming reproducibility.”
“If you choose not to upgrade, we recommend taking your node --offline,” it continued. “Given the known risks, we will not support previous releases, including 26.04.” The message said the scheduled 26.09 release remains planned for late September.
No Binaries, No CVE
Neither the binaries nor an advisory had appeared as of Wednesday afternoon. The most recent tagged release on the Core Lightning repository is v26.06.6, published July 22. The project’s GitHub security advisories page lists none. Neither the Core Lightning account nor Blockstream has posted about it; Blockstream’s feed on Wednesday carried a post-quantum signatures research report and a bitcoin-buying clip from chief executive Adam Back.
That left the warning to travel through third parties. Mark Erhardt, a Bitcoin Core contributor at Localhost Research who goes by Murch, said on stacker.news that he confirmed the message was sent by a moderator in the CLN Discord, then followed up an hour later: “Got a confirmation from one of the CLN maintainers that this is legit, and you should take action.”
Erhardt wrote on X that a “severe” issue had been found and that operators should consider restarting with --offline and watch for the point release.
The Alarm Came From Calle
The message reached a wider audience when Calle, the pseudonymous developer behind the Cashu ecash protocol, amplified it at 2:41 p.m. ET with a sharper framing than the CLN text carries.
“URGENT: Critical vulnerability in Core Lightning,” he wrote. “Blockstream developers urge users to shut down CLN Lightning nodes right NOW!” He followed with instructions to restart with the --offline flag.
The CLN message does not use the word critical, describe a single vulnerability, or say to shut down immediately. It conditions the shutdown on declining to upgrade — an upgrade that is not yet downloadable.
Calle also helps run the Bitcoin Red Team, the volunteer group running AI-assisted audits across Bitcoin’s open-source stack since the Coldcard exploit. He said on Aug. 5 that 16 researchers had filed 4,962 findings across 390 projects in 27.5 hours, including 85 critical and 635 high-severity issues. Core Lightning has attributed the reports it is triaging to “multiple sources” without naming the Red Team.
Ten Days Of AI Reports
Core Lightning first described the pressure publicly on Aug. 13, in a post from its own account that the Discord message later repeated verbatim.
“Like many open source Bitcoin projects, CLN has received a number of AI-generated CVE reports from multiple sources over the past 10 days,” the team wrote. “Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports and develop fixes where needed.”
The team said then that it was aiming to have a point release out “within the next few days.” Thirteen days later, the plan is binaries under embargo.
Fourth Alarm In Four Weeks
The shutdown notice adds a fourth incident to a run of Bitcoin infrastructure failures that began in late July.
A 2021 Coldcard firmware bug that routed seed generation to a weak software randomizer has drained roughly $114 million in BTC since July 30 across more than 5,200 addresses, with victims describing the loss of life savings. On Aug. 3, swap bridge Boltz halted its service indefinitely, saying “attackers now iterate faster than a team our size can find and patch.” Four days later, BTCPay Server told merchants to update to 2.4.2 or shut down over an actively exploited flaw, and Lightning nodes were swept overnight, including one run by hardware wallet maker Foundation.
BTCPay maintainer Nicolas Dorier said that flaw was caught by Sparrow Wallet developer Craig Raw reading logs after losing money, and that the Red Team’s scans had missed it.
Bitcoin traded at $78,490 on Wednesday afternoon, down 0.5% over 24 hours and up about 15% on the week, per CoinGecko, showing no reaction.
Advertisement
Get an edge in Crypto with our free daily newsletter
Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri
90k+ Defiers informed every day. Unsubscribe anytime.


