Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24269Commits captured
20890AI analyses
58High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20890 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36052: ci: Doc: Move all config comments right next to the option they explain

This commit is a documentation and code-style cleanup for Bitcoin Core's continuous integration (CI) scripts. It changes how build configuration strings are formatted in shell scripts so comments can sit next to the options they describe, …

9f059527by merge-script+100−9826 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6949: Manual nightly rustfmt (2026-09-27)

This commit is purely a code formatting cleanup. It adjusts whitespace, line breaks, import order, and adds a single #[rustfmt::skip] annotation so an automated formatter does not reformat a test data array. There are no functional code ch…

f6e33d78by Andrew Poelstra+50−339 files
No security note in commit
High 79 AI analysisMessage 38 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Add 2.4.5 changelog

This commit only adds a changelog entry for BTCPay Server version 2.4.5. The changelog itself describes several security-related fixes and one breaking change that blocks private-network outbound requests by default to prevent server-side …

SSRF mitigation: private-network outbound requests blocked by default for Lightning, LNURL, invoice notifications, and webhooksPermission escalation fix: employees without approved-pull-payment permission can no longer auto-approve overpayment refundsCross-store access fix: invoice searches and payout payment actions scoped to current store
0cb14ec7by Nicolas Dorier+48−01 file
Vendor flagged security relevance
Informational 15 AI analysisMessage 18 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Dummy commit

This commit only reformats code and adds blank lines in a single controller file. No behavior, logic, or security checks were changed. It is a non-functional 'dummy' style/refactoring commit with no security relevance.

8bb7d8eeby Nicolas Dorier+13−81 file
No security note in commit
Informational 4 AI analysisMessage 35 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Bump BTCPayServer.Lightning libraries

This commit only updates two internal library version numbers (BTCPayServer.Lightning.Common from 1.7.2 to 1.7.3 and BTCPayServer.Lightning.All from 1.7.10 to 1.7.11). No code changes are included, and the commit message does not mention a…

a92e8f9eby Nicolas Dorier+2−22 files
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Show fiat API failure as a warning triangle by the balance; aligns with Spice

This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…

09609000by Keeqler+64−541 file
No security note in commit
Moderate 62 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #686 from Foundation-Devices/fix/ecdsa-binding-length-checks

This update fixes a buffer-length bug in the firmware's cryptographic code. Two low-level functions that perform elliptic-curve math were reading exactly 32 bytes from caller-supplied buffers without first checking whether the buffers were…

Out-of-bounds read in cryptographic bindingMissing input validation on length-sensitive bignum deserializationAddition of regression tests for malformed scalar/coordinate lengths
5e4d39baby mjg-foundation+86−03 files
Vendor flagged security relevance
Low 47 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #689 from Foundation-Devices/fix/psbt-witness-iter

This firmware update tightens how Passport handles Bitcoin transaction files (PSBTs). It now rejects unsigned transactions that incorrectly include 'witness' data—extra proof data that belongs only in signed transactions. Before, such malf…

Input validation hardening for PSBT unsigned transaction parsingReplacement of internal ValueError with explicit FatalPSBTIssue for malformed witness dataRemoval of unreachable/dead witness-preservation branch
7f170402by mjg-foundation+112−323 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #693 from Foundation-Devices/fix/hdnode-blank

This commit fixes a security hygiene issue in the Passport hardware wallet firmware. It restores an on-demand 'blank' method for wiping sensitive key data from BIP32 HDNode objects, and starts calling it in places where the code previously…

Restores and uses explicit sensitive-data wiping (HDNode.blank())Adds missing wipe of 64-byte BIP39 master seed in stash.decode()Allocates deserialized HDNodes with a finalizer to ensure heap wipe on GC
2719f20aby mjg-foundation+93−65 files
Vendor flagged security relevance
Moderate 59 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #697 from Foundation-Devices/SFT-8171-bip39-prefix-bounds

This commit fixes two related bugs in the BIP39 word lookup feature used when entering seed words on the Passport hardware wallet. First, the code could write past the end of its result buffer when many words matched a short prefix, becaus…

Out-of-bounds write in C string buffer during prefix matchingInteger signedness issue: negative max_matches wraps to large unsigned valueMissing terminator/separator accounting in length check
735a0d79by mjg-foundation+115−114 files
No security note in commit
Moderate 59 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #698 from Foundation-Devices/SFT-8167-sighash-per-input-type

This commit tightens how the Passport hardware wallet checks the 'sighash' flag for each transaction input based on the input type (old-style, SegWit, or Taproot). It also fixes a crash where a bare assertion with no message would make sig…

Per-input-type sighash validation reduces the attack surface for type confusionLegacy sighash preimage now commits to the actual sighash type instead of a hardcoded SIGHASH_ALL valueAssertions in sighash builders now carry explanatory messages to avoid silent failures
a872cc7fby mjg-foundation+364−134 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →