Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24270Commits captured
20890AI analyses
58High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20890 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: bump version to 2.13.0

This commit is a routine version bump from 2.12.6 to 2.13.0. It only changes version numbers in a header file and translation metadata, plus updates the signed translation bundle timestamp and hash. There are no code behavior changes, no b…

cf19aec3by Jakub Janků+12−129 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

ci: hw: add script for debugging USB permissions

This commit adds a diagnostic script to help debug USB permission problems during automated hardware testing. It does not change any firmware code that runs on Trezor devices, nor does it alter how user funds or secrets are handled. It onl…

efcd53c9by Martin Milata+47−33 files
No security note in commit
Informational 16 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

match the amounts in rbf insufficient fee broadcast errors without backtracking

This commit tightens two text-parsing regular expressions in Sparrow Wallet that read error messages returned by Bitcoin nodes when a Replace-By-Fee (RBF) transaction is rejected for an insufficient fee. The change prevents the regex from …

Regular expression hardening against backtracking and greedy mis-matchParsing of externally supplied error strings from Bitcoin network peersUser-facing fee guidance depends on parsed values
3f36bccfby Craig Raw+2−21 file
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

replace a server alias with its host when the ssl switch differs from the aliased server, and keep the alias when opening server settings

This commit fixes a UI bug in Sparrow Wallet's server settings. When a user had saved a server under a friendly nickname (alias) and then changed the SSL/TLS switch or port, the wallet could end up trying to connect to the wrong server bec…

Connection target confusion due to stale alias after protocol/port changeUI state desynchronization between host alias, port, and SSL togglePotential unintended Electrum server connection
e6efcef3by Craig Raw+11−41 file
No security note in commit
Informational 21 AI analysisMessage 73 · Adequate
LD LedgerLedger Bitcoin app BitcoinHardware wallets

Merge pull request #570 from LedgerHQ/python_bip322

This commit adds support in the Ledger Bitcoin app's Python client for a new PSBT global field called PSBT_GLOBAL_GENERIC_SIGNED_MESSAGE, defined by Bitcoin improvement proposal BIP-322. It lets a PSBT carry a signed message alongside tran…

New PSBT field parsing added with duplicate-key and key-length validationNo buffer overflow or memory-safety issue evident in Python client codeNo mention of vulnerability, CVE, security fix, or attacker scenario in commit or changelog
dab93a1aby Salvatore Ingala+83−24 files
No security note in commit
Low 46 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove incomplete transaction entries before calculating the wallet balance and leave them out of the new transactions notification

This commit fixes a bug in the Sparrow Bitcoin wallet where the wallet could temporarily report an incorrect balance and send misleading 'new transaction' notifications. The problem happened when a transaction moving funds between two of t…

Incorrect balance calculation from incomplete transaction statePremature notification event emitted from unvalidated transaction dataSelf-transfer / partial wallet history can produce misleading UI state
711ded46by Craig Raw+83−62 files
No security note in commit
Moderate 68 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

check stored transaction block hashes against the header store when a wallet is first fetched

This commit fixes a gap in Sparrow Wallet's protection against Bitcoin blockchain reorganizations ('reorgs'). Previously, if a wallet was closed while a reorg happened, the wallet could reopen still believing an old, replaced block proved …

Fixes stale proof acceptance after blockchain reorganizationAdds verification of stored transaction block hashes against local header storeForces re-proof when stored block hash differs from header store at same height
ae0d1ff0by Craig Raw+184−42 files
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'nickez/high-fee-warning-wording'

This commit only changes the wording of an on-screen warning shown to users when a transaction fee is unusually high. The old message read 'The fee is X%\nthe send amount.' and now reads 'Fee is X%\nof the send amount.' The same change is …

d2df29d1by Niklas Dusenlund+1532−987 files
No security note in commit
Low 46 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

apply the wallet lock to label import, sweep and show paynym, and to password prompts and unlocks completing after the wallet was locked

This commit fixes a timing issue in the Sparrow Bitcoin wallet where a user could still perform sensitive actions on a wallet that had been locked while a password prompt or background unlock was in progress. The patch makes sure that if a…

TOCTOU (time-of-check/time-of-use) race between wallet lock state and password-prompt/unlock completionMissing authorization check on sensitive wallet operations (sweep private key, label import, show PayNym)UI control state not synchronized with wallet lock state
26a06c9eby Craig Raw+54−118 files
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'cedwies/agentsMD'

This commit only updates the project's internal coding guidelines document (AGENTS.md). It adds advice about keeping sensitive data in heap-backed storage and avoiding reallocations after writing sensitive data, because discarded memory al…

62e6ee12by Cedric Wiese+3−21 file
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

determine whether the wallet lock screen requires a password from the storage encryption key on each lock and unlock

This commit changes how Sparrow Wallet decides whether to show a password-protected lock screen. Previously, the app checked once when wallet settings changed and cached that result. Now it re-checks every time the wallet is locked or unlo…

Changed encryption-status check from cached/event-driven to per-lock/unlock evaluationRemoved reliance on walletSettingsChanged event to keep encryption status currentSwitched from isEncrypted() (IO-dependent) to direct encryption public key comparison
17ab7f08by Craig Raw+5−131 file
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →