Core Lightning Team Sounds the Alarm as AI Uncovers Critical Flaws
Key Takeaways
- Multiple vulnerabilities were found in Core Lightning (CLN) software.
- Devs are telling node runners to wait for a new upgrade and take current versions offline.
- Reports say artificial intelligence (AI) helped discover the CLN bugs.
Core Lightning Maintainers Race to Deliver Emergency Fix
At the time of writing, the CLN team is preparing signed binaries aimed at fixing the bugs found in the recently disclosed reports. The team is hoping to have a fix within the next 48 hours and full disclosure within two weeks. “Critical vulnerability in Core Lightning,” the software developer Calle wrote on X. “Blockstream developers urge users to shut down CLN Lightning nodes right NOW! Please let everyone know,” the dev added.
As of now, there don’t seem to be any reports of fund losses or any attackers exploiting the issue in the wild. However, the team insists CLN nodes must upgrade and they are also saying that they should take their Lightning nodes offline, so they stop talking to other nodes. “Looks like a severe Core Lightning (CLN) issue was discovered,” the software developer Murch said at 1:41 p.m EDT, explaining that nodes should consider restarting offline.
Lightning Network Capacity Sheds 1,893 BTC in Eight Months
Bitcoin’s Lightning Network is a second layer BTC users leverage to transact off-chain. Topping up and leaving the Lightning Network (opening and closing a channel) requires onchain settlement. On Wednesday at 5 p.m. EDT, the Lightning Network’s capacity stands at 3,998 BTC valued at $313.5 million. Capacity or the public channel balance has been on a significant downturn since May 30 and even more so since Dec. 27, 2025.
Mempool.space statistics show capacity stood at 5,891 BTC on Dec. 27, 2025, which means 32.1% has left over roughly eight months. That’s a decline of 1,893 BTC. The latest vulnerability disclosure comes as a tidal wave of reports, leveraging AI software, have recorded a significant amount of bugs across the industry. Alongside this, at the end of last month, the Coldcard firmware exploit, which caused the losses of nearly 2,000 BTC, was thought to be discovered by AI.
“Wtf is happening. This is really scary,” the X account and pseudonymous bitcoin.org owner Cobra Bitcoin wrote on X.
Boltz Shutdown and AI-Assisted Threats
The CLN vulnerability news follows the recent issues with Boltz, a Lightning, Liquid, and onchain swapping platform. On Aug. 3, Bitcoin.com News reported that following months of AI-assisted attacks, the project shut off all swaps. This impacted other platforms like Aqua, Bull Bitcoin, and Zeus. Bull Bitcoin restored services without waiting for Boltz but Aqua and Zeus are still affected by the issue.
AI-assisted attacks and discovery has the crypto community on edge, to say the least, and the exposed fragility involved with these systems that everyday Bitcoiners rely on continues to add salt to the wound.

