TL;DR:
This Wednesday, August 26, Core Lightning (CLN) developers recommended that operators urgently shut down their nodes or run them offline immediately. The preventive measure is requested ahead of the official release of the security patch.
If you run Core Lightning: when the release is published: upgrade with signed binaries, or start your node with `–offline`.
Details stay under embargo for two weeks. Previous releases, including 26.04, are unsupported.
Full details when the embargo lifts. The 26.09 release is… https://t.co/lruDzbYmd7
— Core Lightning
(@Core_LN) August 26, 2026
The instruction circulated through technical support channels and Lightning Network developer communities. The team’s formal recommendation states that operators unable to update their systems must restart the node daemon using the –offline parameter.
At the time the directive was issued, precompiled binaries containing the fix were not available for public download. According to market reports, the latest stable release tagged in the project’s official GitHub repository is v26.06.6, published on July 22, 2026.
The warning gained visibility when Calle, developer of the Cashu protocol, publicly urged the community to disconnect nodes to prevent operational risks. Mark Erhardt, Bitcoin Core contributor and researcher at Localhost Research, independently confirmed that the request originated from the official maintainers of the Blockstream-developed implementation.
URGENT: Critical vulnerability in Core Lightning
Blockstream developers urge users to shut down CLN Lightning nodes right NOW!
Please let everyone know! pic.twitter.com/4HpobzMs7Y
— calle
(@callebtc) August 26, 2026

The CLN team stated that the bug review began after receiving multiple vulnerability reports generated by artificial intelligence tools throughout August 2026.
“Like many Bitcoin open-source projects, CLN has received a flurry of AI-generated CVE reports from multiple sources. Our team has been working hard to validate, triage these reports, and develop fixes where appropriate,” the Core Lightning team noted in community communications.
Data from the volunteer initiative Bitcoin Red Team indicates that recent automated scans generated 4,962 security findings across 390 ecosystem repositories. According to the group’s report, these reviews identified 85 flaws classified as critical and 635 of high severity across various open-source projects.
This event marks the fourth security advisory involving Bitcoin infrastructure within a 30-day window. In late July 2026, a firmware flaw in Coldcard hardware wallets facilitated the theft of approximately $114 million in BTC, followed by independent technical notices affecting the Boltz and BTCPay Server protocols.
To protect the network from potential exploit vectors before operators can apply the patches, the team decided to keep the precise description of the vulnerabilities under a strict 14-day embargo period.
Lightning Network node operators await the point release containing the corrected binaries, while the broader launch of Core Lightning version 26.09 remains scheduled for late September 2026.