Key facts
- Core Lightning has confirmed multiple vulnerabilities.
- A security update is being prepared.
- Node operators are advised to use offline mode if they cannot install the update immediately.
- The vulnerabilities are separate from previously disclosed issues.
- The project has not disclosed the nature or severity of the vulnerabilities.
Core Lightning, an open-source implementation of Bitcoin's Lightning Network, has confirmed multiple vulnerabilities and is preparing a security update for operators. The project advised node operators to use offline mode if they cannot immediately install the forthcoming update, which keeps their nodes active but disconnected from the network. This measure prevents payments from entering, leaving, or routing through the node while allowing it to follow the Bitcoin blockchain. Core Lightning stated that upgrading is the primary recommendation, with the offline mode serving as an alternative to protect nodes without shutting down the software entirely. These newly confirmed flaws are distinct from remote denial-of-service vulnerabilities that were disclosed in May and July and have since been patched.