The Bitcoin Flash Network software Core Lightning indicates that many of the recent AI-generated security reports have been identified as involving real loopholes. The development team is coordinating the repairs and reminding the node operator to complete the signature validation and installation as soon as possible after the release of the new version.
I'm not going to release details for two weeks.
According to the project party, the team has spent weeks reviewing a large number of AI-generated CVE reports and has concentrated on restoration in the last 10 days. For security reasons, the specific number of relevant loopholes, the mode of attack and whether they have been used will not be made public for the time being, with a minimum of two weeks reserved for developers to issue patches and operators to complete upgrades.
Core Lightning also indicated that it had been planned to launch a small version of the update within a few days, and that it had subsequently been decided to release a signed, retraceable binary document so that node operators could verify and deploy more quickly.
Move to offline mode if upgrade is not possible
Project participants specifically cautioned against recommending that nodes be closed directly. If this cannot be upgraded temporarily, the --offline parameter should be used to restart the node. This would stop connecting to other lightning network nodes and would not transfer payments, but back-office programmes would continue to operate and monitor the Bitcoin main chain.
This is because most of the payments made by the lightning network take place below the chain and only when the tunnel is closed do they return to the Bitcoin chain. If the counterparty initiates the forced closure, the nodes that are still in operation can respond in a timely manner; the nodes that are completely shut down cannot handle such situations and are more risky.
- Offline mode will stop paying for route and reciprocal connection.
- Node can still track the state on the chain.
- The old version will no longer be supported
The project party stated that the earlier version included 26.04 would cease support and that the 26.09 version was still scheduled for release in late September.
AI, speed up the leak detection.
This warning also reflects that AI is accelerating the discovery of a gap in the Bitcoin ecology. In July, the hardware wallet manufacturer Coinkite indicated that the attackers might use AI to check the old code to identify weaknesses in the creation of the Coldcard wallet assistive word, a problem related to the theft of millions of dollars of bitcoin. Earlier this month, Bitcoin Exchange Services Boltz also suspended services on the grounds that suspected assailants had discovered a loophole faster than developers had repaired it.
According to the Voluntary Safety Organization Bitcoin Red Team Statistics, AI Auxiliary Reviews now raise 4962 possible issues in 390 Bitcoin projects, of which 85 and 635 were initially rated as serious and high risk, respectively. However, the organization also acknowledged that some of the results could be misreported.
Calle, a pseudonym developer involved in the organization, said that the current focus was on identifying problems before the attackers. As AI lowers the utilization threshold, it is easier to complete some of the otherwise high-threshold attack processes even for those without a secure background.
