Core Lightning tells node operators to disable experimental features over new fund-risk flaw

- Core Lightning said it is investigating a vulnerability in an experimental feature that could put user funds at risk.
- It told operators using those features to disable them right away.
- The warning affects Bitcoin Lightning node operators running CLN, not Bitcoin itself.
Core Lightning developers have warned anyone running experimental features on their software to disable them or risk losing their funds while the team figures out a recently discovered issue.
The mid-September warning is the second in a matter of weeks, following a late August patch to fix a separate wave of bugs that could have affected businesses, payment providers, and individual operators using Core Lightning’s (CLN) software packages to operate nodes on Bitcoin’s Lightning Network.
The current advisory does not apply to Bitcoin’s main network.
New risk warning for Core Lightning node operatorsÂ
Core Lightning issued a new risk alert on September 15, urging operators to disable any experimental features they have enabled immediately.
Core Lightning did not explain what the experimental feature does or how it could be exploited.
However, the fund loss headache is real as these nodes hold BTC inside payment channels and route funds between users.
Before this September warning, CLN was trying to move on from an eventful August caused by a high volume of AI-generated CVE reports.
The instruction then was to restart nodes with the –offline flag, which cuts peer connections so no payments route through while the software keeps watching the chain.
By August 28, the CLN team told node operators that upgrading to version 26.06.7 was the fix to the issues that emerged during the month.Â
The technical details of that fix were released to GitHub on September 11 after the two-week embargo expired on the period during which attackers could reverse-engineer the patches.Â
AI tools have become a problem for pen-source Bitcoin
The Lightning Development Kit, a separate Lightning Network implementation, faced its own security emergency in August, reinforcing a developing pattern where AI tools are being used to scan open-source Bitcoin code for security flaws.Â
LDK’s maintainers reported no observed losses or exploited applications.
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
What should Core Lightning operators do right now?
Operators running experimental features should disable those features immediately, according to Core Lightning's September 15 advisory, while the team investigates a flaw that may affect user funds.
Does this vulnerability put Bitcoin itself at risk?
No. Coverage of the related August warning noted the flaws affect Core Lightning software, not Bitcoin's base layer, which continues to operate independently, and there was no disclosed evidence of funds being stolen.
What was Core Lightning version 26.06.7?
It was an emergency release the project recommended on August 28 for every node runner, fixing vulnerabilities reported over the prior three weeks; the details were held under a two-week embargo, and the source code was published on September 11 according to the GitHub release page.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















