Developers of Core Lightning, the primary software powering Bitcoin's Layer 2 payment network, have issued an emergency warning after a flood of AI-generated security reports revealed several genuine vulnerabilities in the system. The team is keeping technical details private for two weeks while preparing patches, marking the second Lightning security emergency this month alone.
Market Context
The vulnerability disclosure arrives as Lightning Network adoption has accelerated throughout 2026, with total capacity growing to over 15,000 BTC. Bitcoin's base layer has also seen increased transaction volume following recent fee market shifts, making Layer 2 solutions like Lightning increasingly critical for micro-payments and merchant settlement. The network processes millions of dollars in daily volume across thousands of active nodes globally.
Analysis
Core Lightning said its small development team began receiving a surge of AI-generated vulnerability reports in early August. These automated findings pointed to potential weaknesses where the software could potentially be exploited, leaving developers to manually verify whether each reported issue actually works in practice. Several did, according to the team's statement. The emergence of AI-assisted security research has fundamentally shifted the threat landscape for Bitcoin infrastructure projects. Earlier this month, BTCPay Server suffered a similar vulnerability that exposed credentials controlling Lightning nodes, with attackers draining funds from affected servers before a fix was deployed. That incident underscored how quickly malicious actors can move once vulnerabilities become public. The Core Lightning team specifically instructed operators not to power down their machines if they cannot immediately upgrade, but instead restart the software using --offline mode. This keeps the node watching the Bitcoin blockchain for attempted fraud while severing its connections to other Lightning nodes.
Key Numbers
- 390 Bitcoin repositories swept by Bitcoin Red Team using AI models in late July
- Nearly 5,000 security findings produced in approximately 27 hours of AI scanning work
- 85 vulnerabilities rated critical severity discovered in the repository sweep
- Second Lightning security emergency reported this month following BTCPay Server incident
What to Watch
Core Lightning plans to release signed versions of patched software first, allowing operators to verify authenticity before installation. Full vulnerability details and source code will follow after the two-week embargo period expires. The regularly scheduled Core Lightning 26.09 release remains planned for late September. Separately, a consortium including Coinbase, Block, BitGo, Blockstream and the Bitcoin Policy Institute has requested early access to leading AI models from major labs, arguing that Bitcoin developers are being excluded from tools that threat actors can already access.