
Core Lightning developers are preparing a software release containing fixes for issues identified through AI-generated vulnerability reports, according to messages attributed to the project’s team.
Over the past couple of weeks @Core_LN has been dealing with a large number of AI-generated CVE reports. The team has confirmed issues that need a coordinated fix. They plan signed binaries in the next 48 hours and will hold source for 14 days so the patches can’t be…
— Samson Mow (@Excellion) August 26, 2026
Core Lightning, an open-source implementation of Bitcoin’s Lightning Network, reportedly received multiple CVE reports from several sources over a 10-day period.
The team said its developers and outside contributors had been reviewing the submissions, determining which findings were valid, and developing fixes where necessary.
The developers initially expected to publish a point release within several days.
A subsequent update said the team had changed its approach and would instead distribute signed binaries containing fixes for several reported issues.
Details of the release, including its source code, are expected to remain under embargo for two weeks.
According to the team’s message, the delay is intended to provide operators with time to install the binaries before information about the vulnerabilities becomes public.
The source code, reproducible-build materials, and technical details are expected to be released after the embargo.
Core Lightning developer Christian Decker reported that a binaries-only point release was expected within 48 hours, with the source patches withheld for 14 days to limit the risk of attackers reverse-engineering the fixes.
Uff kind of the panic we were hoping to avoid. To be clear the strategy here is multi-layered: we will publish AA point release in the next 48h, as binaries only, embargoing the source patches for 14 days to prevent attackers reverse engineering them to exploit them.
— Christian Decker (@Snyke) August 26, 2026
JAN3 CEO Samson Mow consolidated Decker’s comments and other team guidance, advising operators to run their nodes with the --offline option until the release became available, verify the developers’ signatures, and then upgrade.
The --offline setting prevents a Core Lightning node from making ordinary peer connections.
While operating in that mode, a node cannot send, receive, or route Lightning payments, although it can continue monitoring the Bitcoin blockchain.
Operators can also reconnect selected peers manually.
A separate social-media post from Cashu developer Calle described the issue as critical and urged operators to shut down their nodes immediately.
🟥 URGENT: Critical vulnerability in Core Lightning
— calle 🟥 (@callebtc) August 26, 2026
Blockstream developers urge users to shut down CLN Lightning nodes right NOW!
Please let everyone know! pic.twitter.com/4HpobzMs7Y
The messages attributed to the Core Lightning team did not provide a severity classification, identify specific CVEs, establish which software versions are affected, or report any exploitation.
The team advised operators to install the signed binaries during the embargo period. Its message recommended that those who do not upgrade take their nodes offline.
Previous releases, including version 26.04, will no longer be supported, according to the team. The planned 26.09 release remains scheduled for late September.
As of August 26th, the embargoed security build was not listed on Core Lightning’s public GitHub releases page.
Technical information about the reported vulnerabilities is expected to become available after the two-week embargo concludes.
