Core Lightning, an open-source implementation of Bitcoin's Lightning Network, has confirmed multiple vulnerabilities and urged node operators to install a forthcoming security update.
The project stated on Thursday that it had been assessing a high volume of artificial intelligence-generated Common Vulnerabilities and Exposures (CVE) reports and determined that several of them are real. Core Lightning advised operators against shutting down their nodes completely, recommending instead that they restart them with the --offline flag, which stops payments from entering, leaving, or routing through the node.
In a later post, Core Lightning clarified that upgrading remains its primary recommendation, while restarting in offline mode serves as an alternative for operators who have not yet upgraded. The guidance allows operators to protect their nodes until an upgrade is completed without shutting down the underlying software entirely.
Core Lightning has not yet disclosed the nature or severity of the vulnerabilities, published CVE identifiers, or reported any related exploitations or financial losses. The newly confirmed flaws are distinct from remote denial-of-service vulnerabilities that were disclosed in May and July and patched in earlier software releases.
The project explained that keeping the daemon active enables it to track the Bitcoin blockchain and respond if a counterparty force-closes a channel, an action a completely stopped node cannot perform. Operators who utilize the --offline setting were advised to remove it after upgrading, or their nodes will remain disconnected from the network.


