Core Lightning has issued an urgent warning for node operators using experimental features to disable them immediately or risk losing funds while developers investigate a recently discovered security issue. The advisory was published on September 15, 2026, and specifically targets the experimental-dual-fund, experimental-splicing, and experimental-peer-storage options.
The warning was highlighted by crypto security commentators including @SlowMist_Team. Core Lightning did not detail how the vulnerable features could be exploited, but the danger is significant because affected nodes hold BTC inside payment channels and route funds between users. The current advisory does not apply to Bitcoin’s main network.
This is the second major warning in weeks. In late August, Core Lightning instructed operators to restart nodes with the –offline flag to cut peer connections after a wave of bugs affecting businesses, payment providers, and individual operators. By August 28, the team said upgrading to version 26.06.7 fixed those issues, with technical details released on GitHub on September 11 after a two-week embargo expired.
The Lightning Development Kit, a separate Lightning Network implementation, also faced a security emergency in August. That incident reinforced a developing pattern in which AI tools are being used to scan open-source Bitcoin code for security flaws. LDK maintainers reported no observed losses or exploited applications.
Node operators are advised to remain alert for an official patch from the Core Lightning team. The vulnerability underscores how experimental features can create real financial risk even when the underlying Bitcoin mainnet is not directly affected.