All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Crypto & Digital Assets

Core Lightning confirms multiple vulnerabilities, prepares security update

Created at 27 Aug · 8:11 AM1 source↑ Market-relevant
IN SHORT

Core Lightning, an open-source implementation of Bitcoin's Lightning Network, has confirmed multiple vulnerabilities and urged node operators to install a forthcoming security update. Operators are advised to use offline mode if they cannot install the update immediately.

Who's Involved

Core Lightning
open-source implementation of Bitcoin's Lightning Network

↳ Why This Matters

The confirmation of vulnerabilities in Core Lightning, a key implementation of the Bitcoin Lightning Network, raises concerns about the security of transactions and the network's overall stability. Operators must take immediate action to protect their nodes and funds.

Key facts

  • Core Lightning has confirmed multiple vulnerabilities.
  • A security update is being prepared.
  • Node operators are advised to use offline mode if they cannot install the update immediately.
  • The vulnerabilities are separate from previously disclosed issues.
  • The project has not disclosed the nature or severity of the vulnerabilities.

Core Lightning, an open-source implementation of Bitcoin's Lightning Network, has confirmed multiple vulnerabilities and is preparing a security update for operators. The project advised node operators to use offline mode if they cannot immediately install the forthcoming update, which keeps their nodes active but disconnected from the network. This measure prevents payments from entering, leaving, or routing through the node while allowing it to follow the Bitcoin blockchain. Core Lightning stated that upgrading is the primary recommendation, with the offline mode serving as an alternative to protect nodes without shutting down the software entirely. These newly confirmed flaws are distinct from remote denial-of-service vulnerabilities that were disclosed in May and July and have since been patched.

Frequently asked questions

Core Lightning is an open-source implementation of Bitcoin's Lightning Network, a second-layer solution designed to enable faster and cheaper Bitcoin transactions.

Operators are strongly advised to install the forthcoming security update. As an alternative, they can restart their nodes with the "--offline" flag to prevent transactions until they can upgrade.

Restarting a Core Lightning node with the "--offline" flag prevents payments from entering, leaving, or routing through the node, effectively disconnecting it from network activity while keeping the software running to follow the Bitcoin blockchain.

Core Lightning has not disclosed any related exploitation or losses, nor has it published specific CVE identifiers for the vulnerabilities.

What Happens Next

01Operators are expected to install the forthcoming security update.
02Operators using offline mode will need to remove the setting after upgrading.
CME Headlines
  • Bitcoin futures break $80,000 as consumer confidence drops.
    25 Aug · 6:57 PM
  • Bitcoin futures break $80,000 as consumer confidence drops.
    25 Aug · 6:57 PM
  • Can Bitcoin's Long-Term Catalysts Overcome Recent Headwinds?
    24 Aug · 3:00 PM

How It Developed

Core Lightning confirmed multiple vulnerabilities after assessing AI-generated CVE reports.
Node operators are urged to install a forthcoming security update.
An alternative is to restart nodes with "--offline" to prevent transactions.
Keeping the daemon active in offline mode allows nodes to follow the Bitcoin blockchain.
The confirmed flaws are separate from previous remote denial-of-service vulnerabilities.

Sources

T1
Core Lightning confirms multiple vulnerabilities, prepares security updateCore Lightning advised operators to use offline mode if they do not install the forthcoming update, keeping their nodes active but disconnected.Cointelegraph

Related Stories

Coldcard Bug Prompts Shift to Multi-Vendor Multisig for Bitcoin Security
26 Aug · 11:46 PM
Ethereum Devs Propose Deposit Contract Overhaul to Quantum-Proof Staking
26 Aug · 3:11 PM
StarkWare tests quantum-resistant Bitcoin transaction on mainnet
27 Aug · 4:25 AM
Bitcoin Wallets Dormant for Over a Decade Move $40M in One Week
26 Aug · 6:51 PM
Chainalysis: $457B in taxable crypto activity, CARF misses most
26 Aug · 6:06 PM