Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24269Commits captured
20890AI analyses
58High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20890 analyses
Highest risk·RSS
Low 28 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #701 from Foundation-Devices/SFT-8161-use-bip39-generate

This commit removes the `bip39.generate()` function from the firmware's exposed programming interface when a build flag called `USE_BIP39_GENERATE` is set to 0. Passport already creates wallet seed phrases through a different internal path…

Reduction of firmware API surface for unused secret-generation functionDefensive build-time gating with preprocessor flagRegression test verifying absence of a sensitive function
fe0e08b3by mjg-foundation+50−04 files
No security note in commit
Moderate 60 AI analysisMessage 81 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Merge PR 'Fail held HTLC failures when force-closing' (#5050)

This commit fixes a bug in the Lightning Dev Kit where a forwarded payment could get permanently stuck if a channel was force-closed at exactly the wrong moment. Normally, when the next node in a route rejects a payment, that rejection is …

Fixes a stuck-HTLC / payment resolution failure on force-closeAdds counterparty_failed_htlcs to ChannelForceClosed monitor update stepDrains monitor_pending_failures into the closing monitor update
e8c3f656by Matt Corallo+449−76 files
No security note in commit
Low 37 AI analysisMessage 58 · Thin
LL Lightning LabsLND BitcoinLightning Network

Merge pull request #11191 from bitromortac/2604-bolt12-1h

This commit finalizes LND's new BOLT 12 codec package. It is mostly a refactor: public Encode/Decode helpers are renamed to internal encodeBech32/decodeBech32, validation helpers are unexported, and new helpers such as EncodeSigned and Off…

Removed decoder-side length limits on BOLT 12 bech32 strings; caller must bound inputAdded EncodeSigned entry points that enforce signature presence and verification before serialization leaves the nodeSigning now runs writer validation before producing a signature
f3a8f4e8by ziggieXXX+1275−51221 files
No security note in commit
Informational 24 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #705 from Foundation-Devices/SFT-7322-pairing-secret-erased-word

This commit fixes a minor sanity check in the bootloader that generates a device pairing secret. The original code compared only the lowest 8 bits of a 32-bit word against 0xff, when it intended to check the entire 32-bit word against 0xff…

Boundary/policy check corrected to compare full 32-bit erased-flash patternNew regression test compiles production provisioning function with deterministic RNGComment clarifies bootloader provisioning entropy source constraints
74581cffby mjg-foundation+80−12 files
No security note in commit
Informational 24 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #706 from Foundation-Devices/SFT-8178-core-urtypes-migration

This commit updates a Rust library dependency (foundation-urtypes) used in the Passport hardware wallet firmware to a newer version that includes 'arena fixes.' The code changes rename some data types to use borrowed references (e.g., HDKe…

Dependency update to foundation-urtypes 0.5.1 and foundation-arena 0.1.1Commit title mentions 'arena fixes'Type migration from owned/borrowed types to explicit reference types (Ref suffix)
bbcf8e93by mjg-foundation+80−263 files
No security note in commit
Moderate 59 AI analysisMessage 81 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Merge PR 'Credit remote HTLC fulfills on remote HTLC adds' (#5043)

This commit fixes how Lightning channels account for money that is about to be freed up when a payment succeeds or fails. Previously, the code could incorrectly let a node spend funds that were not yet actually available, or conversely blo…

Channel balance/liquidity accounting changeHTLC fulfillment credit timing changePrevention of premature spending of unacknowledged HTLC removals
0645450aby Matt Corallo+505−1513 files
No security note in commit
Moderate 59 AI analysisMessage 60 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: propagate TLS verification to native and RPC wallets

This commit fixes how Java wallet code passes TLS/SSL certificate verification settings down to the underlying native Monero wallet and to RPC wallets. Previously, the Java layer could request 'verify the certificate' or 'allow any certifi…

TLS/SSL verification preference now propagated across JNI to native walletRPC wallet now translates connection sslVerify into ssl_allow_any_cert and ssl_support parametersConnection equality/hashCode now includes sslVerify, preventing silent mismatches
43c2a9ecby woodser+240−4010 files
No security note in commit
Moderate 68 AI analysisMessage 68 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Fail held HTLC failures when force-closing

This commit fixes a bug in the Lightning Dev Kit where a forwarded payment failure could get permanently lost if a channel was force-closed at exactly the wrong moment. Previously, when the other side of a channel told us an HTLC (a condit…

Fixes a state-loss race that could leave forwarded HTLCs unresolvedPrevents a secondary force-close caused by an un-failed HTLCAdds ChannelMonitorUpdateStep::ChannelForceClosed field counterparty_failed_htlcs
bfc96786by elnosh+449−76 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix mobile screen transitions

This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…

9456bbbdby Keeqler+3−11 file
No security note in commit
Moderate 64 AI analysisMessage 81 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Merge PR 'Drop since-applied blocked monitor updates before the stale-channel check' (#5046)

This patch fixes a bug in the Lightning Dev Kit's channel startup logic. Previously, if a user's ChannelManager state was older than their ChannelMonitor, the code would force-close the channel and incorrectly fail backwards (cancel) any H…

Force-close triggered by stale ChannelManager stateIncorrect HTLC failure backwards for already-committed HTLCsChannelMonitor/ChannelManager state desynchronization
49ed7c35by Matt Corallo+148−42 files
No security note in commit
Informational 18 AI analysisMessage 50 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Fix create password screen showing up on mobile; format

This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…

Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
6483d8a1by Keeqler+163−729 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →