npub1m2…lr8p9 on Nostr: In August the Core Lightning maintainers told node operators to upgrade or run ...
In August the Core Lightning maintainers told node operators to upgrade or run --offline. There was nothing to upgrade to for another two days, and when v26.06.7 arrived it was binaries only, with the source held back a further two weeks so attackers could not reverse-engineer the fixes. We (me + AI models) used that window. Ten AI models, one public source tree, the same five sentences of prompt, under $100 between them. Every report was hashed into the Bitcoin blockchain with OpenTimestamps as it was finished, nine days before upstream published the source, so none of it can be backdated.
Reading source, the models found four of the nine defects the release fixed. Running "strings" on the public download found five more, and one of those is theft that pays for itself: as a forwarding node you refund the sender upstream, and the peer then claims the outgoing HTLC on-chain with the preimage it held the whole time. You pay twice and collect nothing. It was findable because the patched binary carries upstream's own new log line, FUNDS LOSS, which names the function, and the vulnerable code sat in the public v26.06.6 tree throughout. Three models at three price points landed on it within minutes of the download. The embargo hides the patch, but not the mechanism.
Write-up:
https://juraj.bednar.io/en/blog-en/2026/09/18/ten-ai-models-vs-embargoed-core-lightning-a-case-study-of-ai-for-auditing/Full case-study, reports and timestamps:
https://github.com/jooray/CLN-incident-audit-202608Published at
2026-09-18 09:34:00 UTCEvent JSON
{
"id": "86393a5ab1978ec1bc34cad54f440728a6335a6fe74d47260feed485484c5102",
"pubkey": "dab6c6065c439b9bafb0b0f1ff5a0c68273bce5c1959a4158ad6a70851f507b6",
"created_at": 1789724040,
"kind": 1,
"tags": [],
"content": "In August the Core Lightning maintainers told node operators to upgrade or run --offline. There was nothing to upgrade to for another two days, and when v26.06.7 arrived it was binaries only, with the source held back a further two weeks so attackers could not reverse-engineer the fixes. We (me + AI models) used that window. Ten AI models, one public source tree, the same five sentences of prompt, under $100 between them. Every report was hashed into the Bitcoin blockchain with OpenTimestamps as it was finished, nine days before upstream published the source, so none of it can be backdated.\n\nReading source, the models found four of the nine defects the release fixed. Running \"strings\" on the public download found five more, and one of those is theft that pays for itself: as a forwarding node you refund the sender upstream, and the peer then claims the outgoing HTLC on-chain with the preimage it held the whole time. You pay twice and collect nothing. It was findable because the patched binary carries upstream's own new log line, FUNDS LOSS, which names the function, and the vulnerable code sat in the public v26.06.6 tree throughout. Three models at three price points landed on it within minutes of the download. The embargo hides the patch, but not the mechanism.\n\nWrite-up: https://juraj.bednar.io/en/blog-en/2026/09/18/ten-ai-models-vs-embargoed-core-lightning-a-case-study-of-ai-for-auditing/\nFull case-study, reports and timestamps: https://github.com/jooray/CLN-incident-audit-202608",
"sig": "1d7d70e6d3cbab5d26622239fa9d7c5c9ef06e5ec9a86131ebaf9a3fce26edfef255412acb64100a77fb478e0b3012bf7e002957ba9d3cdb13882f3705953328"
}