Core Lightning tells node operators to upgrade after confirming security flaws

49 minutes ago 2



Core Lightning has confirmed multiple security vulnerabilities in its Bitcoin Lightning Network software and has urged node operators to install an upcoming security update or temporarily run their nodes offline. Summary Core Lightning confirmed several vulnerabilities after reviewing a large number of AI generated CVE reports. Node operators were urged to install the security update, with offline mode offered as a temporary option for those awaiting an upgrade. Running a node offline stops Lightning payments and routing while allowing the daemon to continue monitoring the Bitcoin blockchain. Core Lightning has not disclosed the flaws’ severity, CVE identifiers or any evidence of exploitation or related losses. Core Lightning said Thursday that its developers had been reviewing a large number of AI-generated Common Vulnerabilities and Exposures reports and confirmed that several submissions identified real problems requiring fixes. The project advised operators to upgrade as its main recommendation. Operators who have not installed the security release can restart Core Lightning with the –offline option, which prevents the node from connecting to peers and stops payments from enter...

Read Entire Article