Core Lightning developers urged node operators to shut down their systems or use an offline command to protect against a critical vulnerability. A fix utilizing signed binaries with hidden source code will be published within 48 hours to prevent reverse-engineering of the patch.

BTCPay Server disabled default routes to Core Lightning and Eclair following a surge of AI-generated vulnerability reports. Eclair released version 0.14.2 as AI tools begin identifying flaws in Bitcoin's Lightning infrastructure faster than human security researchers.

Sign in to suggest edits

Key sources

  1. SOURCE@callebtc“upgrade with signed binaries, or start your node with `--offline`”x.com
  2. SUPPORT@pashov“Hidden source code (with the idea of patches not being reverse-engineerable) binaries, holding a fix, will be published in <48hrs”x.com
  3. SUPPORT@tftc21“BTCPay Server has disabled routes to Core Lightning and Eclair in its default deployment”x.com
  4. SUPPORT@callebtc“Eclair v0.14.2 is out”x.com
  5. SUPPORT@callebtc“Blockstream developers urge users to shut down CLN Lightning nodes right NOW!”x.com
  6. SUPPORT@callebtc“Restart your CLN node with `--offline`”x.com
  7. SUPPORT@tftc21“AI is now finding real vulnerabilities in Bitcoin's Lightning infrastructure faster than human security researchers”x.com
  8. SUPPORT@murchandamus“be on the lookout for the point release coming in the next few days”x.com
Markdown