As of the article's writing, the CLN team is preparing signed binaries intended to patch bugs identified in recently published reports. The team hopes to release a fix within the next 48 hours and fully disclose the information within two weeks. "Critical vulnerability in Core Lightning," wrote software developer Kalle on X. "Blockstream developers strongly urge users to immediately shut down CLN Lightning nodes! Please spread the word," the developer added.
At this moment, there appear to be no reports of fund losses or of attackers exploiting this vulnerability in real-world conditions. However, the team insists that CLN nodes must be updated and also recommends disconnecting Lightning nodes from the network so they cease interacting with other nodes. "Looks like a serious issue discovered in Core Lightning (CLN)," stated software developer Murch at 13:41 Eastern Time (EDT), explaining that nodes should consider restarting in offline mode.
Lightning Network Capacity Drops by 1,893 $BTC Over Eight Months
The Bitcoin Lightning Network is a second layer that $BTC users employ for conducting off-chain transactions. Topping up and exiting the Lightning Network (opening and closing a channel) require on-chain settlements. At 17:00 Eastern Time (EDT) on Wednesday, the Lightning Network's capacity was 3,998 $BTC valued at $313.5 million. Capacity, or the public channel balance, has been declining significantly since May 30, and particularly sharply since December 27, 2025.
Mempool.space statistics show that on December 27, 2025, capacity was 5,891 $BTC, meaning a 32.1% drop over roughly eight months. This is a decrease of 1,893 $BTC. The latest vulnerability disclosure comes amidst a wave of reports that a significant number of bugs across the industry have been identified using AI-powered software. Alongside this, late last month, a vulnerability in Coldcard firmware that led to the loss of nearly 2,000 $BTC was believed to have been discovered using AI.
"What the hell is going on? This is truly terrifying," wrote the owner of the X account and bitcoin.org, operating under the pseudonym Cobra Bitcoin, on X.
Boltz Shutdown and AI-Enabled Threats
The news of the CLN vulnerability surfaced amidst recent issues with Boltz — a swap platform for Lightning, Liquid, and on-chain. On August 3, Bitcoin.com News reported that after months of AI-powered attacks, the project suspended all swap operations. This impacted other platforms like Aqua, Bull Bitcoin, and Zeus. Bull Bitcoin resumed operations without waiting for a fix from Boltz, but Aqua and Zeus are still experiencing issues.
AI-powered attacks and their detection are, to say the least, keeping the crypto community on edge, and the exposed vulnerabilities in these systems, which everyday Bitcoin users rely on, continue to fuel the fire.
end-content





