This week,
@Core_LN
is telling node operators to patch their code. Not to shut anything down.
The Core Lightning maintainers have spent two weeks hand-checking a flood of machine-generated vulnerability reports.
"Like many open source Bitcoin projects, CLN has received a number of AI-generated CVE reports from multiple sources over the past 10 days."
Watch what it did to curl, the small piece of software running quietly inside almost every device you own. curl ran a bug bounty from 2019, paid out more than $90,000 for 81 real vulnerabilities, and shut the program down in February. Its confirmed-vulnerability rate fell from roughly 15% to under 5%. In June the maintainers announced they would not read a single security report for the whole of July. The Internet Bug Bounty had already paused new submissions in March for the same reason.
Now the other half of the year. On January 27 OpenSSL shipped a patch for 12 zero-days, bugs nobody had ever reported, and an AI system found every one of them. Three had been sitting in that code since the late 1990s, through millions of CPU-hours of fuzzing, Google's included.
Both sides of security picked up the same new tools at the same time, and only one of those sides has to publish, get reviewed and be right.
That is now pointed at Bitcoin. Wallets, nodes, Lightning implementations, signing devices, most of it maintained by small teams and unpaid contributors. And Bitcoin is the one system with no database to quietly edit afterwards.
Our read is that the next twelve months put Bitcoin's stack through the hardest audit money has ever been given, and that plenty of it looks alarming while it happens. Twelve zero-days was not OpenSSL failing. It was OpenSSL getting harder in an afternoon.
Patch your node this week. That is the small job.
The big one is already running.
