The Bitcoin Lightning Network achieves that Core Lightning (CLN) sends a security alert that suggests that the node operator upgrades as soon as possible after the release of the restored version; if this is not possible for the time being, consideration may be given to downlineing the node. The team has yet to disclose the details of the loopholes, but the security response has been activated.
Multiple reports received within 10 days
Core Lightning developed and maintained by Blockstream. The project team indicated that multiple AI-generated gap reports had been received from multiple sources over the past 10 days, and that developers and open-source contributors were verifying whether or not those issues had been established.
The team had planned to issue a small version of the update within a few days, directly repairing the related issues and then adjusting the disposal programme.
Let's start with the fixer.
Core Lightning now decides to provide a signed binary to fix the file, but the information relating to the loophole will remain confidential for two weeks. According to the developer, this was intended to reduce the risk of the attacker being able to analyse the backsliding through patches and to create a tool for use.
The project maintainer indicated that the team strongly recommended that all users complete the upgrade during the confidential period. For unupgraded operators, the team recommends that at least nodes be restarted. Previous versions, including 26.04, will not continue to receive support during this security response.
Community challenge communication
The developer Calle, associated with the Cashu ecology, described this as a serious loophole and called upon the Core Lightning node operator to close the node directly. Some community members questioned the fact that the user had first learned about the matter through a Discord intercept, rather than seeing the official account issue.
After an external challenge, Core Lightning then issued an official warning to the nodal operator. To date, however, the team has not disclosed the specific type or actual severity of the gap.
