Slow Mist: A vulnerability exists in a certain experimental feature of Core Lightning, which may put user funds at risk
According to Slow Fog's disclosure, Core Lightning (CLN) has an experimental feature vulnerability that may put user funds at risk. Core Lightning's official statement indicates that they are investigating the vulnerability and recommend that all nodes with experimental features enabled immediately disable them and wait for a patch. High-risk options include --experimental-dual-fund, --experimental-splicing, and --experimental-peer-storage.
Slow Fog stated that similar issues were fixed in August, where remote peers could specify arbitrary or even zero fees in channel opening or fund adjustment protocols. Local nodes would sign and write to the database without additional verification, potentially forcing nodes to incur abnormal fees or even trigger a crash loop, leading to long-term offline status for the nodes.
Node operators are advised to immediately disable or remove all experimental parameters; do not completely shut down the nodes, but use offline mode to retain on-chain monitoring capabilities to prevent peers from forcefully closing channels while the node is offline; verify signatures after the official patch is released before upgrading, and be cautious of fake patch links shared by impersonating official accounts.






