Particle.news

Core Lightning Orders Nodes Offline as Patch Is Readied

Developers will distribute signed binary fixes but are withholding source details for 14 days to limit exploit risk.

Overview

  • Core Lightning maintainers told operators to take vulnerable nodes offline because known flaws affect current releases and a public patch has not yet been published.
  • The advisory followed a burst of AI-generated CVE reports that developers say surfaced exploitable issues after roughly ten days of incoming reports.
  • Core Lightning plans to ship signed binary releases that contain fixes while delaying source-level details under a 14-day embargo to reduce the chance attackers reverse-engineer the vulnerability.
  • A third-party vendor released an update that forces CLN nodes offline to preserve on-chain funds and channel state, and a separate vulnerability affecting LND versions before 0.21.0 was disclosed at the same time.
  • There are no confirmed fund losses or active exploits so far but public Lightning capacity has fallen significantly and widespread shutdowns will cut routing liquidity, raise payment failures, and squeeze operators who earn fees from routing.