Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24260Commits captured
20887AI analyses
57High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20887 analyses
Highest risk·RSS
Low 45 AI analysisMessage 18 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Refactor SSRF

This commit is a code cleanup that changes how BTCPay Server blocks outgoing requests to internal/local network addresses (SSRF protection). It moves the protection logic from a shared service into an extension method used when configuring…

SSRF protection logic refactored but preservedUnit tests verifying SSRF rejection for Bitpay and Webhooks removedManual unprotected-handler test path removed in LightningTests
ed51828aby Nicolas Dorier+26−698 files
No security note in commit
Low 38 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #710 from Foundation-Devices/SFT-8207-bound-provisioning-rng

This commit adds a safety cap to how many times the Passport bootloader can retry picking a random pairing secret if the first word keeps looking like erased flash. It also adds tests that simulate hardware random-number-generator failures…

Bounded retry loop prevents potential denial-of-service/infinite loop during provisioningFatal error on RNG exhaustion stops provisioning before flash writes or secure-element setupTests added/expanded to verify retry bound and RNG failure handling
0b1e97c2by mjg-foundation+187−382 files
No security note in commit
Informational 22 AI analysisMessage 76 · Adequate
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#34729: Reduce log noise

This commit is a logging cleanup. It reduces the severity of many routine or remote-triggered error messages so they don't flood node operators with false alarms, and adds a helper that issues a warning only the first time a problem occurs…

Logging-only change; no memory safety, cryptography, consensus, or authorization logic alteredNew `LogWarnThenDebug` helper uses a static `std::atomic<bool>` to warn once then log as debugOne functional behavior change: `AddCScript` return value is now checked in `bitcoin-tx` and wallet tests, and oversized redeemScript logs at Info instead of Error
cf80493eby Ava Chow+85−5413 files
No security note in commit
High 76 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #640 from Foundation-Devices/SFT-4502-fix-p2wpkh-nested-in-p2sh-hash-change-validation

This firmware update fixes a bug in how Passport hardware wallets decide whether a Bitcoin transaction's 'change' output really belongs to your wallet. Before the fix, a malicious or buggy companion app could trick the device into treating…

Fixes change-output validation bypass in P2SH-P2WPKH where only pubkey hash was checked, not the full redeem scriptAdds address-format enforcement (BIP purpose vs output type) preventing cross-account-type change spoofingPrevents too-short or unknown derivation paths from being silently classified as change
5842b65cby mjg-foundation+308−327 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Informational 15 AI analysisMessage 73 · Adequate
EP Elements ProjectCore Lightning BitcoinLightning Network

contrib: add jaonoctus's public key

This commit simply adds a public PGP key file for a release signer named jaonoctus. It is a housekeeping change to make the key available in the repository so people can verify release signatures. There is no code change, no vulnerability,…

9ba88c5dby jaonoctus+90−01 file
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →