AI-generated bug reports hit Bitcoin’s Lightning Network, and some were real

The flood of machine-written vulnerability reports was mostly noise, and then some of it was not.

Abstract EMRGNG cover image for a story about Bitcoin

Core Lightning, one of the main software implementations of Bitcoin’s Lightning payment network, told node operators on 26 August that several security flaws flagged in a wave of AI-generated vulnerability reports are genuine. Operators who cannot upgrade at once were advised to switch to a mode called offline, which stops a node routing payments while it keeps watching the blockchain, rather than shut the machine down.

The project said it had taken in a high volume of automatically generated CVE reports over about ten days, from several sources, reviewed them, and prepared fixes. The specifics are under a two week embargo so operators can patch before the details become public. A release numbered 26.09 is due in late September, and the older 26.04 version will lose support.

This is close to the scenario security researchers described once language models became competent at reading code. Reports arrive faster than a small volunteer team can check them, most are mistaken or duplicated, and the work of sorting them lands on the maintainers, unpaid for the most part. This time the flood carried something real, which does not make the next one easier to handle or cheaper to process.

Core Lightning has not said how many reports it received, how many proved genuine, or how serious they are, and will not until the embargo ends. Operators are meanwhile running reduced nodes on the strength of a warning that deliberately holds back the detail. Whether the other Lightning implementations carry the same flaws has not been addressed.

Read more here.

More from EMRGNG