Core Lightning warns that node operators are offline, and the fix patch has not yet been released
Core Lightning maintains that node operators should shut down their nodes unless they upgrade to an unreleased version. This warning was spread via Discord and amplified by Cashu protocol developer Calle, who stated that there is a serious vulnerability. The fix binary has not yet been released, and the details of the vulnerability are under a two-week confidentiality period.
This is the fourth security alert for Bitcoin infrastructure in four weeks. Previously, a Coldcard firmware vulnerability led to approximately $114 million in BTC being stolen, and issues have also arisen with Boltz and BTCPay Server. The CLN team stated that they have received multiple AI-generated CVE reports in the past 10 days and are intensifying verification and fixes.






