Skip to main content
AVOID.NET

Core Lightning (CLN)

avoid.net/core-lightning-cln→52/100·72% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·48x4fM…QoKW
last updated 2026-10-04

Summary

Core Lightning (CLN) is an open-source Bitcoin Lightning Network implementation developed and maintained by Blockstream, originally released in 2015 as c-lightning. As of October 2026, Blockstream has confirmed that attackers are actively targeting CLN nodes running v26.06.7 or earlier, exploiting vulnerabilities that include a channel-closing flaw capable of causing fund loss and a REST-interface memory exhaustion bug that can crash nodes remotely. A patch (v26.06.8) has been available since September 22, 2026, but uptake remains incomplete across the operator base.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Core Lightning (CLN)?

Timeline(10 events)

1 August 2015

Blockstream releases c-lightning, the first Lightning Network implementation, led by Rusty Russell.

Bitcoin Magazine

1 January 2018

c-lightning enters Bitcoin mainnet production use with the launch of the Blockstream Store.

Core Lightning official website

1 June 2022

Blockstream rebrands c-lightning to Core Lightning (CLN) to signal long-term focus on spec compliance and interoperability.

Blockstream blog

1 July 2026

Twin memory-exhaustion DoS vulnerabilities affecting CLN's connectd and gossipd daemons are publicly disclosed on Delving Bitcoin.

TFTC

14 August 2026

Bitcoin Red Team begins submitting AI-generated CVE reports against Core Lightning repositories using the Kimi K3 model, generating ~4,962 findings across 390+ Bitcoin repositories.

The Bitcoin Manual

26 August 2026

Blockstream issues emergency advisory directing all CLN node operators to take nodes offline immediately due to multiple confirmed critical vulnerabilities. No active exploitation or fund losses confirmed at this stage.

TFTC

28 August 2026

Core Lightning v26.06.7 released, addressing the vulnerabilities identified through the August AI-generated CVE campaign.

crypto.news

16 September 2026

Core Lightning team investigates new issues potentially affecting experimental features and operator funds.

crypto.news

22 September 2026

Core Lightning v26.06.8 released, patching three confirmed bug classes: a crash-on-send flaw, a REST-interface memory exhaustion vulnerability, and a channel-closing bug exposing operators to penalty-based fund loss.

The Currency Analytics

2 October 2026

Blockstream issues urgent public advisory confirming attackers are actively targeting CLN nodes running v26.06.7 or earlier. Operators urged to upgrade to v26.06.8 immediately or restart in offline mode. No confirmed fund losses disclosed.

TFTC
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 18 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 10/3/2026, 11:07:02 PM

last updated: 10/4/2026, 1:20:54 AM

avoid.net — verified advice for a post-truth world