Core Lightning Network developers and the Blockstream team issued an emergency warning to node operators, revealing that critical vulnerabilities have been identified in the Lightning Network client. The team is urging all users to shut down their CLN nodes immediately or restart with the –offline flag until signed fix binaries are released within the next few days.

Situation and urgent action required
The situation has escalated beyond the earlier denial-of-service vulnerabilities discovered in July by developer Chandra Pratap during the Summer of Bitcoin program. Those earlier flaws allowed remote attackers to exhaust node memory and cause crashes by flooding nodes with channel update messages or fake short channel IDs.
While patches were released in versions v26.04 and v26.06rc2, the new alert suggests additional, more serious vulnerabilities have been validated.
The CLN response
According to the Core Lightning team, announced on X, they have received several AI-generated Common Vulnerabilities and Exposures reports from multiple sources over the past 10 days.
The small team, alongside open-source contributors, has been working intensively to validate and triage these reports and develop fixes where needed.
So, rather than publishing the point release this week, the team will make binaries available containing fixes for many of the reported vulnerabilities.
However, the details of the release will remain under embargo for two weeks, but the binaries will be accompanied by the team’s signatures confirming reproducibility.
During the embargo period, the CLN team strongly encourages everyone to upgrade. For those who choose not to upgrade, the team recommends taking the node offline.
Given the known risks, they will not support previous releases, including 26.04, and the 26.09 release remains planned for late September.
Separate LND risk confirmed
This alert follows a separate disclosure on August 13, 2026, about a critical vulnerability in Lightning Network Daemon, another Lightning Network client.

That flaw could allow a malicious channel peer to trigger a full-channel wipeout during a Bitcoin reorganization. The vulnerability affects LND versions below 0.21.0, and operators are urged to update immediately.
Separating the threats: CLN’s challenge versus BTCPay’s breach
The CLN alert arrives alongside a separate, actively exploited vulnerability in BTCPay Server’s LND integration that has already drained funds from several merchants, including hardware wallet manufacturer Foundation and Bitcoin publication Citadel21.
That exploit used a bug in .macaroon file access to completely take over nodes. While the CLN issues are still under wraps and haven’t been spotted in the wild yet, the BTCPay situation shows just how much damage these Lightning implementation flaws can cause in real life.
Node operators running either client should treat the CLN warning with appropriate urgency.



