Key highlights:

  • Core Lightning issues a security warning to node operators amid AI-reported vulnerabilities
  • Operators need to either wait for the security update to upgrade or keep their nodes offline
  • Blockchain infrastructure has been facing increasing security vulnerabilities

Core Lightning developers have issued an unusual security warning to node operators as the team is working to address several security vulnerabilities. Operators are asked to take their nodes offline if they cannot upgrade to an upcoming security release. However, the fix is not available yet, leaving operators with little choice but to wait or shut down their nodes.

Core Lightning Tells Node Operators to Upgrade or Go Offline Over AI-Reported Bugs


Core Lightning maintainers have warned node operators to install an upcoming security release or otherwise run their nodes offline, as the team works through multiple AI-generated vulnerability… pic.twitter.com/t6nqFtVwEp

— Wu Blockchain (@WuBlockchain) August 27, 2026

Core Lightning urges operators to shut down until security fix

The latest reports reveal Core Lightning’s security warning to node operators to either install the upcoming update or take their nodes offline. While the patched version has not been released yet, the team is still working through several vulnerability reports. The message read,

“The details of the release will remain under embargo for two weeks. The binaries will be accompanied by the team’s signatures confirming reproducibility…If you choose not to upgrade, we recommend taking your node –offline. Given the known risks, we will not support previous releases, including 26.04.”

Notably, Core Lightning is one of the major implementations used in the Bitcoin Lightning Network. It helps process faster, lower-cost BTC transactions through off-chain payment channels. This makes the security of its nodes important to the broader network.

AI-reported bugs trigger fresh security concerns

The warning came as the recent AI-assisted research flagged several vulnerabilities, in addition to other major security issues. The team initially issued the warning via the Core Lightning Discord, and later it was shared on Stacker News. As of now, the operators are not sure about what specific bugs are being addressed or how they could affect their nodes.

The team has also advised operators who cannot upgrade to restart their nodes using the offline option. As noted by the team, the older versions, including 26.04, will no longer receive support due to the security risks. The next major 26.09 release is set for late September. Thus, operators are left with two choices. They have to either wait for the security update and upgrade then or keep their nodes offline until the issues are fixed.

It is worth noting that Core Lightning initially revealed the issue on August 13, 2026. The platform stated that they received several AI-generated CVE reports from different sources over a 10-day period. The team has been checking these reports and identifying the real vulnerabilities. All these days, the platform has been preparing to release the update, but it has yet to go public. Now, the team is preparing security-update binaries under an embargo.

Bitcoin infrastructure faces security incidents

Significantly, the latest warning comes on the heels of a series of security problems facing bitcoin infrastructure. On July 30, Coldcard experienced a major hack resulting from a weak random number generator, leading to a loss of about $114 million in BTC. Another major incident followed within days, with swap service Boltz suspending operations. While attackers moved stolen funds faster, the team couldn’t restrict it.

In early August, BTCPay Server issued a warning to merchants to upgrade to version 2.4.2 or shut down amid an actively exploited vulnerability. In addition, several Lightning nodes were also affected.