Core Lightning developers are preparing a software release containing fixes for issues identified through AI-generated vulnerability reports, according to messages attributed to the project’s team.

Core Lightning, an open-source implementation of Bitcoin’s Lightning Network, reportedly received multiple CVE reports from several sources over a 10-day period. 

The team said its developers and outside contributors had been reviewing the submissions, determining which findings were valid, and developing fixes where necessary.

The developers initially expected to publish a point release within several days. 

A subsequent update said the team had changed its approach and would instead distribute signed binaries containing fixes for several reported issues.

Details of the release, including its source code, are expected to remain under embargo for two weeks. 

According to the team’s message, the delay is intended to provide operators with time to install the binaries before information about the vulnerabilities becomes public. 

The source code, reproducible-build materials, and technical details are expected to be released after the embargo.

Core Lightning developer Christian Decker reported that a binaries-only point release was expected within 48 hours, with the source patches withheld for 14 days to limit the risk of attackers reverse-engineering the fixes. 

JAN3 CEO Samson Mow consolidated Decker’s comments and other team guidance, advising operators to run their nodes with the --offline option until the release became available, verify the developers’ signatures, and then upgrade.

The --offline setting prevents a Core Lightning node from making ordinary peer connections. 

While operating in that mode, a node cannot send, receive, or route Lightning payments, although it can continue monitoring the Bitcoin blockchain. 

Operators can also reconnect selected peers manually.

A separate social-media post from Cashu developer Calle described the issue as critical and urged operators to shut down their nodes immediately. 

The messages attributed to the Core Lightning team did not provide a severity classification, identify specific CVEs, establish which software versions are affected, or report any exploitation.

The team advised operators to install the signed binaries during the embargo period. Its message recommended that those who do not upgrade take their nodes offline.

Previous releases, including version 26.04, will no longer be supported, according to the team. The planned 26.09 release remains scheduled for late September.

As of August 26th, the embargoed security build was not listed on Core Lightning’s public GitHub releases page

Technical information about the reported vulnerabilities is expected to become available after the two-week embargo concludes.