MEMPOL!TICS
← BACK TO THE BOARD
TechnologistTHU AUG 27 · UPDATED 11:16 AM ET · @Core_LN + @callebtc + TFTC · DEVELOPING

CLN TO NODE RUNNERS: UPGRADE OR GO OFFLINE — START9 SHIPS AN OFFLINE-BY-DEFAULT UPDATE THE SAME DAY — FIX DETAILS SEALED FOR TWO WEEKS

Core Lightning’s maintainers confirmed multiple critical vulnerabilities and told every node runner the same thing: get off the network until you are patched. The bugs arrived through AI-generated vulnerability reports — a roughly ten-day wave of them — and the fix details stay sealed until the week of September 9 so attackers cannot reverse-engineer an exploit before most nodes update; lead maintainer Christian Decker says that is exactly why source patches are being held back. No lost funds have been reported and no attack has been seen in the wild. The working guidance: on StartOS, update from the marketplace — the new package starts your node offline automatically; everyone else, the signed binaries are being prepared and had not appeared on the official GitHub releases page as of Thursday morning — verify there, then upgrade promptly. Until then, restart with the offline flag: it closes peer connections but keeps the daemon watching the chain, which a full shutdown does not. Version 26.04 is no longer supported. The Technologist read: this is the immune system doing its job in public — embargo, packaged safe defaults, downstream services pulling routes within hours. The same AI wave that hit Boltz and BTCPay found these bugs before an attacker did. The response is working. Verify, then upgrade.
READ THE COVERAGE →
@Core_LN + CLN team via @callebtc + @murchandamus · Start9 release · Bitcoin.com + TFTC (expanded Aug 27) · Updated Thu Aug 27