Core Lightning Critical Vulnerabilities Force Emergency Shutdown
Core Lightning maintainers confirmed multiple critical vulnerabilities on August 26 and are urging all CLN node operators to take nodes offline immediately. A signed emergency patch is expected within 48 hours. No confirmed fund losses as of disclosure.

CLN maintainers confirmed multiple critical bugs on August 26. All node operators are told to go offline now.
Key takeaways
- Core Lightning maintainers confirmed multiple critical vulnerabilities on August 26 and are urging every CLN node operator to take nodes offline immediately and stop peering with the network.
- No confirmed fund losses or active exploitation have been reported as of disclosure, meaning the responsible-disclosure pipeline between the Bitcoin Red Team and CLN maintainers is functioning as intended.
- Lightning Network public channel capacity has declined significantly since December 27, 2025, and a cluster of AI-surfaced security events across CLN, BTCPay, and Boltz in the same month is now a plausible behavioral driver alongside any macro pressure.
Core Lightning maintainers confirmed multiple critical vulnerabilities on August 26 and issued an immediate directive: take your CLN node offline and stop communicating with the network. A signed binary emergency patch is being prepared, with a fix expected within approximately 48 hours and full public disclosure expected within approximately two weeks, per the initial disclosure, confirm both timelines remain current before acting on them.
As of the time of disclosure, there are no confirmed reports of fund losses or active exploitation in the wild.
What Happened and What to Do Right Now
Bitcoin developer and Bitcoin Red Team member Calle (@callebtc) posted the initial public warning on X about the CLN vulnerabilities and urged node operators to shut down immediately.
Bitcoin Core contributor Murch (@murchandamus) also posted on August 26 that a severe Core Lightning (CLN) issue had been discovered and that nodes should consider restarting offline.
The CLN team is preparing signed binaries for an emergency release. Until that release is confirmed on the ElementsProject/lightning GitHub releases page, every CLN operator should be offline. Do not rely on social media for the all-clear. Watch the GitHub releases page directly and apply only the signed binary when it drops.
This is not CLN's first significant vulnerability event. A twin memory-exhaustion DoS vulnerability was disclosed on Delving Bitcoin in July 2026, just weeks before this disclosure.
The Capacity Chart Is Telling You Something
Lightning Network public channel capacity has declined sharply from the 5,891 BTC recorded on December 27, 2025, verify the current figure at mempool.space before citing a specific number, as it changes continuously. The direction of the trend is unambiguous: capacity is down materially over roughly eight months.
The reflexive read is bearishness on Bitcoin's price or a slowdown in Lightning adoption. There is a more precise explanation available now. Rational node operators who have watched Boltz shut down all swaps on August 3 following months of AI-assisted attacks, then watched the BTCPay LND macaroon exploit drain Lightning nodes, and now see CLN flag multiple critical bugs in the same month, may be pulling liquidity for straightforward operational risk reasons. The capacity chart reflects behavior, not just sentiment. Note: the Boltz shutdown also disrupted services for Aqua and Zeus users, verify current status of both at publish time, as circumstances may have changed, though Bull Bitcoin restored services independently without waiting for Boltz.
The Bitcoin Red Team's AI audit sweep across 390-plus open-source Bitcoin repositories produced roughly 4,962 findings in approximately 27.5 hours, funded partly by OpenSats and using Kimi K3 as the primary frontier model. Calle previously noted they were "averaging on the order of 1 critical exploit per hour per person." The CLN disclosure is a direct output of that pipeline.
The thesis here is specific and falsifiable: the responsible-disclosure process is working. The Red Team found these bugs. CLN maintainers responded. No funds are confirmed lost. If active exploitation with confirmed fund losses emerges before the patch ships, or if evidence surfaces that an adversary knew about this vulnerability before the Red Team flagged it, that conclusion collapses and the situation becomes a materially different story.
What has permanently changed is the pace at which attack surface can be probed, by defenders and attackers alike. Operators running CLN are now in an environment where that surface is being swept at machine speed. The correct response is process, not panic: go offline, monitor the GitHub releases page, apply the signed patch, and treat social media alerts as the start of your verification process, not the end of it.
What to Watch
The approximately two-week full disclosure window is the next hard deadline. If a GitHub advisory or signed release drops before then, that document becomes the primary record and will specify affected version ranges. Monitor the ElementsProject/lightning releases page directly, no official advisory had been posted as of time of writing; check at publish time and promote it to primary source if live. If confirmed fund losses or evidence of prior exploitation surface before the patch ships, the situation escalates significantly.
Sources
- Calle (@callebtc) X post, Aug. 26, 2026, verify URL and verbatim content at publish time
- Murch (@murchandamus) X post, Aug. 26, 2026, verify URL and verbatim content at publish time
- mempool.space Lightning Network capacity
- ElementsProject/lightning GitHub releases
- Delving Bitcoin: Twin memory-exhaustion DoS vulnerability in Core Lightning (July 2026)
Frequently Asked Questions
Version-specific scope has not been publicly disclosed. Full CVE details are expected within approximately two weeks. Until the signed release and advisory are published, treat all currently running CLN versions as potentially affected and keep nodes offline.
Channel funds are the primary exposure. Keeping a CLN node active and peering with the network while unpatched leaves open channels potentially reachable by any actor aware of the vulnerability. The maintainers' directive is unambiguous: go offline now, not after the next block. Routing fees are not worth the counterparty risk until the signed patch is deployed.
The Bitcoin Red Team, led by Calle and Rob Hamilton, ran an AI-assisted security audit across 390-plus open-source Bitcoin repositories, generating roughly 4,962 findings in approximately 27.5 hours. The primary model used was Kimi K3 from Moonshot AI. The effort was funded in part by OpenSats. The CLN vulnerabilities disclosed on August 26 emerged from that sweep, demonstrating both the capability and the urgency of AI-accelerated security auditing on open-source Bitcoin infrastructure.


