Core Lightning has confirmed several vulnerabilities in its software and is working on a security update, according to Cointelegraph. With these issues out in the open, the team has dropped some key recommendations for node operators to help manage risk until the patch goes live.

Confirmed Vulnerabilities

The project officially acknowledged that a number of vulnerabilities have been found in its codebase. While the specifics weren't disclosed, devs are already on it and prepping a security update to address the issues.

Advice for Node Operators

If you’re not planning to install the upcoming update right away, the team recommends switching your nodes to offline mode. This keeps your node running but cuts it off from the network—a temporary move to limit any fallout until the patch is released and applied.

What’s Next

The team is finalizing the security update. Until you’ve patched your node, stick with the offline mode approach if you’re holding off on the update. Once the patch drops, operators should update their software ASAP to lock down the newly discovered vulnerabilities.