← Core Lightning (CLN)1 decision on this page
Audit log
Every state-changing event for Core Lightning (CLN): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-03 23:07:12ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 453,076,595
- sig
48x4fMrAKpg6…ygAPQoKWexplorer ↗- hash
E3imi61Uch9s…tZfgetU7sha256 → base58
verifying row…full verify ↗canonical bytes (20454 B) ▸
{"actor":"system:backfill","investigation_id":"61a612f9-9887-4f5c-8afd-032e9ef11785","kind":"publish","page_slug":"core-lightning-cln","published_at":"2026-10-03T23:07:12.081Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Core Lightning (CLN)","sections":[{"content":"Core Lightning (CLN), formerly known as c-lightning, is a lightweight, specification-compliant implementation of the Bitcoin Lightning Network protocol. Developed by Blockstream, it was first released in August 2015 and has been running on Bitcoin mainnet since early 2018. The software is written primarily in C and follows a modular, plugin-first architecture in which the core daemon is intentionally minimal and extended functionality is delivered through plugins communicable via JSON-RPC. CLN is one of three principal Lightning Network implementations alongside LND (Lightning Labs) and Eclair (ACINQ). LND holds the largest share of public nodes by most estimates; CLN occupies a smaller portion of the network but is considered a reference implementation for BOLT specification compliance. The GitHub repository is maintained at ElementsProject/lightning.","heading":"Project Overview","severity":"low","sources":[{"credibility":1,"name":"Core Lightning official website","type":"official","url":"https://corelightning.org/"},{"credibility":1,"name":"Blockstream blog: c-lightning Is Now Core Lightning","type":"official","url":"https://blog.blockstream.com/en-c-lightning-is-now-core-lightning/"},{"credibility":1,"name":"GitHub: ElementsProject/lightning","type":"official","url":"https://github.com/ElementsProject/lightning"},{"credibility":2,"name":"Bitcoin Magazine: Core Lightning Rebrand","type":"news_article","url":"https://bitcoinmagazine.com/technical/blockstream-core-lightning-bitcoin-rebrand"}]},{"content":"On October 2, 2026, Blockstream issued an urgent security advisory confirming that attackers are actively targeting CLN nodes running version 26.06.7 or earlier. The team stated that it had received reports of attackers probing unpatched nodes in the wild. As of the advisory date, the development team had not disclosed which specific vulnerabilities were being exploited, nor had they publicly confirmed whether any operator funds had been successfully stolen. The team withheld certain test suites from the public repository to prevent attackers from reverse-engineering the exact attack surface while operators complete upgrades. Blockstream recommended that operators unable to upgrade immediately restart their nodes in offline mode as a temporary mitigation. Coverage of the active-exploitation warning was reported by multiple crypto news outlets including TFTC, Bitcoin.com News, CoinCentral, CrowdFundInsider, and Blockonomi.","heading":"Active Exploitation Warning — October 2026","severity":"critical","sources":[{"credibility":2,"name":"TFTC: Core Lightning Active Attack Warning — Upgrade to v26.06.8","type":"news_article","url":"https://www.tftc.io/core-lightning-active-attack-warning-upgrade-v26-06-8"},{"credibility":2,"name":"Bitcoin.com News: Bitcoin Lightning Nodes Targeted as Core Lightning Sounds Alarm","type":"news_article","url":"https://news.bitcoin.com/security/bitcoin-lightning-nodes-targeted-core-lightning-sounds-alarm/"},{"credibility":2,"name":"CoinCentral: Core Lightning Nodes Under Attack","type":"news_article","url":"https://coincentral.com/core-lightning-nodes-under-attack-bitcoin-developers-urge-immediate-upgrade"},{"credibility":2,"name":"CrowdFundInsider: Core Lightning Warns Attackers Targeting Unpatched Nodes","type":"news_article","url":"https://www.crowdfundinsider.com/2026/10/315000-open-source-bitcoin-lightning-implementation-core-lightning-warns-that-attackers-are-targeting-unpatched-nodes/"},{"credibility":2,"name":"Blockonomi: Active Exploits Hit Core Lightning","type":"news_article","url":"https://blockonomi.com/active-exploits-hit-core-lightning-developers-issue-critical-security-alert"},{"credibility":2,"name":"crypto.news: Bitcoin Lightning Security Alert — Attackers Target Older CLN Nodes","type":"news_article","url":"https://crypto.news/bitcoin-lightning-security-alert-issued-as-attackers-target-older-core-lightning-nodes/"}]},{"content":"Version 26.06.8, released on September 22, 2026, closes three confirmed bug classes identified through responsible disclosure. First, a crash-on-send flaw can disable a sender's node under certain conditions. Second, a memory exhaustion vulnerability in the REST interface allows a remote party to trigger unbounded memory consumption, crashing the node; this vector can be used for griefing and, if timed with a force-close, could reduce the victim's ability to respond to on-chain events. Third, and most critically, a channel-closing bug causes a node to misidentify a revoked commitment transaction as a legitimate cooperative close, causing the node to miss the penalty transaction window. Under Lightning Network protocol rules, publishing a revoked commitment gives the counterparty the right to claim all channel funds via a penalty transaction; a node that does not recognize the revocation and broadcast the appropriate response loses those funds. No CVE identifiers had been publicly assigned as of the advisory date. The release notes credited Bitcoin Red Team and twelve other named individuals and organizations, as well as at least one anonymous reporter, for responsible disclosure.","heading":"Vulnerability Details — v26.06.8 Patch","severity":"critical","sources":[{"credibility":2,"name":"TFTC: Core Lightning Active Attack Warning — Upgrade to v26.06.8","type":"news_article","url":"https://www.tftc.io/core-lightning-active-attack-warning-upgrade-v26-06-8"},{"credibility":2,"name":"The Currency Analytics: Core Lightning v26.06.8 Patches Node Crashes and Fund-Loss Bugs","type":"news_article","url":"https://thecurrencyanalytics.com/bitcoin/core-lightnings-version-26-06-8-patches-node-crashes-and-fund-loss-bugs-299472"},{"credibility":2,"name":"CoinCentral: Core Lightning Nodes Under Attack","type":"news_article","url":"https://coincentral.com/core-lightning-nodes-under-attack-bitcoin-developers-urge-immediate-upgrade"}]},{"content":"Prior to the October 2026 active-exploitation alert, Core Lightning underwent a separate security crisis in August 2026. Beginning around August 14–26, the development team received an unusually large volume of AI-generated CVE reports, reportedly produced by the Kimi K3 model from Moonshot AI during a Bitcoin Red Team audit that scanned over 390 repositories and generated approximately 4,962 findings in roughly 27.5 hours. On August 26, 2026, Blockstream issued an emergency advisory directing all CLN node operators to take their nodes offline immediately, citing multiple confirmed critical vulnerabilities. The advisory stated that a signed emergency patch was expected within approximately 48 hours and that full public disclosure would follow within two weeks. No confirmed fund losses or active exploitation were reported at the time of the August disclosure. Version 26.06.7 was subsequently released on August 28, 2026, addressing the issues identified at that stage. This August incident also followed a July 2026 disclosure of twin memory-exhaustion DoS vulnerabilities affecting the connectd and gossipd daemons, which could be triggered by remote peers sending malformed or excessive messages.","heading":"August 2026 AI-Generated CVE Crisis and Emergency Shutdown","severity":"high","sources":[{"credibility":2,"name":"TFTC: Core Lightning Critical Vulnerabilities — Emergency Shutdown","type":"news_article","url":"https://www.tftc.io/core-lightning-critical-vulnerabilities-emergency-shutdown"},{"credibility":2,"name":"TFTC: Core Lightning AI CVE Emergency Vulnerabilities August 2026","type":"news_article","url":"https://www.tftc.io/core-lightning-ai-cve-emergency-vulnerabilities-august-2026"},{"credibility":2,"name":"Cyber Kendra: Core Lightning Vulnerabilities Prompt CLN Offline Warning","type":"news_article","url":"https://www.cyberkendra.com/2026/08/core-lightning-vulnerabilities-prompt.html"},{"credibility":2,"name":"The Bitcoin Manual: Inside Core Lightning's AI-Triggered Security Crisis","type":"news_article","url":"https://thebitcoinmanual.com/articles/cln-ai-triggered-security-crisis/"},{"credibility":2,"name":"Bitcoin.com News: Core Lightning Team Sounds the Alarm as AI Uncovers Critical Flaws","type":"news_article","url":"https://news.bitcoin.com/security/core-lightning-team-sounds-the-alarm-as-ai-uncovers-critical-flaws/"}]},{"content":"The 2026 CLN incidents occurred within a broader pattern of Lightning Network security disclosures across implementations. In August 2026, Lightning Labs addressed an update_fee exploit in LND that allowed channel initiators to manipulate fees and potentially leave victims with unrecoverable funds. Separately, a 2026 security patch sweep covered LDK, CLN, and Eclair. An earlier widely-cited cross-implementation concern was the replacement-cycling attack class, catalogued as CVE-2023-40231 through CVE-2023-40234, which exploited interactions between Bitcoin's transaction replacement rules and Lightning's HTLC settlement process. In late 2022, a separate incident targeted LND specifically when developer Burak exploited a consensus discrepancy between Bitcoin Core and btcd to force LND nodes off-sync. None of these prior incidents directly implicated Core Lightning in fund losses attributable to the software itself. Core Lightning's vulnerabilities in 2026 are specific to its own implementation and do not affect Bitcoin's base layer or other Lightning implementations.","heading":"Broader Lightning Network Security Context","severity":"medium","sources":[{"credibility":2,"name":"shattered.io: Lightning Network Security Patches 2026","type":"research","url":"https://shattered.io/lightning-network-security-patches-2026/"},{"credibility":2,"name":"crypto.news: Bitcoin Lightning Security Alert — Attackers Target Older CLN Nodes","type":"news_article","url":"https://crypto.news/bitcoin-lightning-security-alert-issued-as-attackers-target-older-core-lightning-nodes/"}]},{"content":"Node operators running CLN v26.06.7 or earlier are directly exposed to active exploitation as of the October 2, 2026 advisory. The channel-closing bug poses direct financial risk: a successfully exploited node may lose all funds in affected channels to a counterparty's penalty transaction. The REST-interface memory exhaustion bug poses availability risk and, in combination with a forced channel close, could reduce an operator's ability to broadcast protective on-chain transactions within the time-sensitive dispute window. Blockstream's recommended actions as of the advisory are: (1) upgrade to v26.06.8 immediately from the official GitHub release page; (2) if immediate upgrade is not possible, restart the node with the --offline flag to block incoming peer connections and halt routing. The development team advised against relying on social media for an all-clear signal and directed operators to monitor the ElementsProject/lightning GitHub releases page directly.","heading":"Operator Exposure and Recommended Actions","severity":"critical","sources":[{"credibility":2,"name":"TFTC: Core Lightning Active Attack Warning — Upgrade to v26.06.8","type":"news_article","url":"https://www.tftc.io/core-lightning-active-attack-warning-upgrade-v26-06-8"},{"credibility":2,"name":"TFTC: Core Lightning Critical Vulnerabilities — Emergency Shutdown","type":"news_article","url":"https://www.tftc.io/core-lightning-critical-vulnerabilities-emergency-shutdown"},{"credibility":1,"name":"GitHub: ElementsProject/lightning (official release page)","type":"official","url":"https://github.com/ElementsProject/lightning"}]},{"content":"As of October 2, 2026, Blockstream had not publicly confirmed that any operator funds were successfully stolen as a result of the active exploitation campaign. The team confirmed receipt of reports of attackers targeting unpatched nodes but declined to specify which vulnerabilities were being used or whether the attacks had resulted in completed fund theft. The absence of a public confirmation of losses does not mean no losses occurred; the development team's stated policy of withholding technical specifics during the patch-uptake window also extends to incident impact details. This page will be updated when Blockstream or credible independent sources provide confirmed loss figures or post-incident disclosures.","heading":"Fund Losses and Exploitation Confirmation Status","severity":"high","sources":[{"credibility":2,"name":"crypto.news: Bitcoin Lightning Security Alert — Attackers Target Older CLN Nodes","type":"news_article","url":"https://crypto.news/bitcoin-lightning-security-alert-issued-as-attackers-target-older-core-lightning-nodes/"},{"credibility":2,"name":"Blockonomi: Active Exploits Hit Core Lightning","type":"news_article","url":"https://blockonomi.com/active-exploits-hit-core-lightning-developers-issue-critical-security-alert"}]}],"sources_used":[{"credibility":1,"name":"Core Lightning official website","type":"official","url":"https://corelightning.org/"},{"credibility":1,"name":"GitHub: ElementsProject/lightning","type":"official","url":"https://github.com/ElementsProject/lightning"},{"credibility":1,"name":"Blockstream blog: c-lightning Is Now Core Lightning","type":"official","url":"https://blog.blockstream.com/en-c-lightning-is-now-core-lightning/"},{"credibility":2,"name":"TFTC: Core Lightning Active Attack Warning — Upgrade to v26.06.8","type":"news_article","url":"https://www.tftc.io/core-lightning-active-attack-warning-upgrade-v26-06-8"},{"credibility":2,"name":"TFTC: Core Lightning Critical Vulnerabilities — Emergency Shutdown","type":"news_article","url":"https://www.tftc.io/core-lightning-critical-vulnerabilities-emergency-shutdown"},{"credibility":2,"name":"TFTC: Core Lightning AI CVE Emergency Vulnerabilities August 2026","type":"news_article","url":"https://www.tftc.io/core-lightning-ai-cve-emergency-vulnerabilities-august-2026"},{"credibility":2,"name":"Bitcoin.com News: Bitcoin Lightning Nodes Targeted as Core Lightning Sounds Alarm","type":"news_article","url":"https://news.bitcoin.com/security/bitcoin-lightning-nodes-targeted-core-lightning-sounds-alarm/"},{"credibility":2,"name":"Bitcoin.com News: Core Lightning Team Sounds the Alarm as AI Uncovers Critical Flaws","type":"news_article","url":"https://news.bitcoin.com/security/core-lightning-team-sounds-the-alarm-as-ai-uncovers-critical-flaws/"},{"credibility":2,"name":"CrowdFundInsider: Core Lightning Warns Attackers Targeting Unpatched Nodes","type":"news_article","url":"https://www.crowdfundinsider.com/2026/10/315000-open-source-bitcoin-lightning-implementation-core-lightning-warns-that-attackers-are-targeting-unpatched-nodes/"},{"credibility":2,"name":"CoinCentral: Core Lightning Nodes Under Attack","type":"news_article","url":"https://coincentral.com/core-lightning-nodes-under-attack-bitcoin-developers-urge-immediate-upgrade"},{"credibility":2,"name":"Blockonomi: Active Exploits Hit Core Lightning","type":"news_article","url":"https://blockonomi.com/active-exploits-hit-core-lightning-developers-issue-critical-security-alert"},{"credibility":2,"name":"crypto.news: Bitcoin Lightning Security Alert — Attackers Target Older CLN Nodes","type":"news_article","url":"https://crypto.news/bitcoin-lightning-security-alert-issued-as-attackers-target-older-core-lightning-nodes/"},{"credibility":2,"name":"The Currency Analytics: Core Lightning v26.06.8 Patches Node Crashes and Fund-Loss Bugs","type":"news_article","url":"https://thecurrencyanalytics.com/bitcoin/core-lightnings-version-26-06-8-patches-node-crashes-and-fund-loss-bugs-299472"},{"credibility":2,"name":"The Bitcoin Manual: Inside Core Lightning's AI-Triggered Security Crisis","type":"news_article","url":"https://thebitcoinmanual.com/articles/cln-ai-triggered-security-crisis/"},{"credibility":2,"name":"Cyber Kendra: Core Lightning Vulnerabilities Prompt CLN Offline Warning","type":"news_article","url":"https://www.cyberkendra.com/2026/08/core-lightning-vulnerabilities-prompt.html"},{"credibility":2,"name":"Tangem: Core Lightning Issues Urgent Upgrade Warning","type":"news_article","url":"https://tangem.com/en/news/security/43568-core-lightning-issues-urgent-upgrade-warning/"},{"credibility":2,"name":"Bitcoin Magazine: Core Lightning Rebrand","type":"news_article","url":"https://bitcoinmagazine.com/technical/blockstream-core-lightning-bitcoin-rebrand"},{"credibility":2,"name":"shattered.io: Lightning Network Security Patches 2026","type":"research","url":"https://shattered.io/lightning-network-security-patches-2026/"}],"summary":"Core Lightning (CLN) is an open-source Bitcoin Lightning Network implementation developed and maintained by Blockstream, originally released in 2015 as c-lightning. As of October 2026, Blockstream has confirmed that attackers are actively targeting CLN nodes running v26.06.7 or earlier, exploiting vulnerabilities that include a channel-closing flaw capable of causing fund loss and a REST-interface memory exhaustion bug that can crash nodes remotely. A patch (v26.06.8) has been available since September 22, 2026, but uptake remains incomplete across the operator base.","timeline":[{"date":"2015-08-01","event":"Blockstream releases c-lightning, the first Lightning Network implementation, led by Rusty Russell.","source":"Bitcoin Magazine","source_url":"https://bitcoinmagazine.com/technical/blockstream-core-lightning-bitcoin-rebrand"},{"date":"2018-01-01","event":"c-lightning enters Bitcoin mainnet production use with the launch of the Blockstream Store.","source":"Core Lightning official website","source_url":"https://corelightning.org/"},{"date":"2022-06-01","event":"Blockstream rebrands c-lightning to Core Lightning (CLN) to signal long-term focus on spec compliance and interoperability.","source":"Blockstream blog","source_url":"https://blog.blockstream.com/en-c-lightning-is-now-core-lightning/"},{"date":"2026-07-01","event":"Twin memory-exhaustion DoS vulnerabilities affecting CLN's connectd and gossipd daemons are publicly disclosed on Delving Bitcoin.","source":"TFTC","source_url":"https://www.tftc.io/core-lightning-critical-vulnerabilities-emergency-shutdown"},{"date":"2026-08-14","event":"Bitcoin Red Team begins submitting AI-generated CVE reports against Core Lightning repositories using the Kimi K3 model, generating ~4,962 findings across 390+ Bitcoin repositories.","source":"The Bitcoin Manual","source_url":"https://thebitcoinmanual.com/articles/cln-ai-triggered-security-crisis/"},{"date":"2026-08-26","event":"Blockstream issues emergency advisory directing all CLN node operators to take nodes offline immediately due to multiple confirmed critical vulnerabilities. No active exploitation or fund losses confirmed at this stage.","source":"TFTC","source_url":"https://www.tftc.io/core-lightning-critical-vulnerabilities-emergency-shutdown"},{"date":"2026-08-28","event":"Core Lightning v26.06.7 released, addressing the vulnerabilities identified through the August AI-generated CVE campaign.","source":"crypto.news","source_url":"https://crypto.news/bitcoin-lightning-security-alert-issued-as-attackers-target-older-core-lightning-nodes/"},{"date":"2026-09-16","event":"Core Lightning team investigates new issues potentially affecting experimental features and operator funds.","source":"crypto.news","source_url":"https://crypto.news/bitcoin-lightning-security-alert-issued-as-attackers-target-older-core-lightning-nodes/"},{"date":"2026-09-22","event":"Core Lightning v26.06.8 released, patching three confirmed bug classes: a crash-on-send flaw, a REST-interface memory exhaustion vulnerability, and a channel-closing bug exposing operators to penalty-based fund loss.","source":"The Currency Analytics","source_url":"https://thecurrencyanalytics.com/bitcoin/core-lightnings-version-26-06-8-patches-node-crashes-and-fund-loss-bugs-299472"},{"date":"2026-10-02","event":"Blockstream issues urgent public advisory confirming attackers are actively targeting CLN nodes running v26.06.7 or earlier. Operators urged to upgrade to v26.06.8 immediately or restart in offline mode. No confirmed fund losses disclosed.","source":"TFTC","source_url":"https://www.tftc.io/core-lightning-active-attack-warning-upgrade-v26-06-8"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 3799ed2f-7388-4b61-a5f6-6af6d340f80e
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.