Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24270Commits captured
20890AI analyses
58High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20890 analyses
Highest risk·RSS
Informational 24 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

skip recipient parsing of the send tab pay to field while it shows the name of a selected paynym

This commit fixes a UI bug in Sparrow Wallet's 'Send' tab. When a user selected a PayNym (a privacy-focused contact name), the wallet was still trying to parse that display name as if it were a Bitcoin address, payment code, or web address…

UI state confusion between display name and parseable recipientUnintended network resolution triggered by display textPotential recipient misparsing leading to wrong transaction destination
8b9074e0by Craig Raw+81−791 file
No security note in commit
Informational 17 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove the redundant merkle proof flag from the cormorant server capability

This commit removes a special flag telling Sparrow not to request cryptographic transaction proofs when connected to a backend called 'cormorant'. The change makes cormorant behave like other local-node backends, which is described as remo…

Change touches server capability / transaction verification logicRemoves a previously special-cased merkle-proof flag for one backendNo explicit security language in commit title or message
c2555d22by Craig Raw+2−42 files
No security note in commit
Moderate 55 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #659 from Foundation-Devices/fix/unicode-settings-save

This update fixes a bug in how the Passport hardware wallet saves user settings that contain non-English characters (Unicode). Previously, the code measured text size in characters instead of encoded bytes, so a setting that looked small c…

Buffer size check used character length instead of encoded byte length, leading to potential slot overflow with Unicode dataOversized settings could previously be partially written or silently ignored instead of failing atomicallyMultisig wallet save task now rolls back in-memory state on any save failure and reports distinct errors
273e2d99by Jacksper13+230−206 files
No security note in commit
High 70 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #696 from Foundation-Devices/fix/bootloader-image-bounds

This update fixes two related weaknesses in the Passport hardware wallet's bootloader. First, it corrects a size-limit check so a malicious or malformed firmware update cannot claim a firmware length larger than the actual space reserved f…

Bounds-check correction for declared firmware image lengthFail-closed behavior added when secure-element timestamp read returns zeroPrevention of downgrade bypass via zero/tampered timestamp
482f40fcby Jacksper13+23−13 files
Vendor flagged security relevance
Low 29 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #695 from Foundation-Devices/fix/pin-build-inputs

This commit locks down the versions of software building blocks used when compiling Passport's Rust code. It adds the '--locked' flag to cargo commands and pins the exact version of a code-generation tool (cbindgen). This is a hardening ch…

Adds --locked to cargo commands to enforce Cargo.lock resolutionPins cbindgen to exact version '=0.24.5'Updates critical-section dependency lockfile entry from 1.1.2 to 1.2.0
072bf252by Jacksper13+13−105 files
No security note in commit
Moderate 62 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6954: units: serialize unsigned amounts as u64

This commit fixes a mismatch in how unsigned Bitcoin amounts were serialized versus deserialized when using certain compact binary formats. Previously, an unsigned amount (like 100 satoshis) was written as a signed number, which caused for…

Data integrity bug: serialized values decode to different numeric values in varint binary formatsRange-check failure: Amount::MAX and large values near the cap fail deserialization after round-tripSerde serialize/deserialize hint mismatch for unsigned amount types
295c9d8aby Andrew Poelstra+66−112 files
No security note in commit
Informational 18 AI analysisMessage 45 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'fix/bb02-empty-passphrase-scroll'

This commit changes the on-screen confirmation text from "Use empty passphrase?" to "Use empty\npassphrase?" — adding a line break so the message fits properly on the device's small display. It appears to be a UI layout fix, not a security…

No security-relevant code paths modifiedNo input validation, authentication, or cryptographic changesUI string formatting change only
a1319588by beerosagos+2−22 files
No security note in commit
Informational 15 AI analysisMessage 83 · Strong
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #703 from Foundation-Devices/sft-8192-rename-fake-test-doubles-to-mock-across-the-passport-test

This commit is a simple renaming of test helper classes from 'Fake*' to 'Mock*' across seven test files. It does not change any production firmware code, behavior, or security logic. It is purely a code-style/test-maintenance change.

2d38c30dby Jacksper13+116−1167 files
No security note in commit
Low 30 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #652 from Foundation-Devices/taproot-bip322-message-signing

This commit adds support for signing text messages with Bitcoin Taproot (P2TR) addresses using the BIP-322 standard. It introduces a new helper module, wires it into existing message-signing flows, and adds unit tests. There is no direct e…

New cryptographic signing path using BIP-322/BIP-341Private key handling in `sign_text_file_task.py` via `stash.SensitiveValues` and `node.private_key()`Signature format change from raw 65-byte recoverable ECDSA to base64 BIP-322 witness
070eb777by Jacksper13+255−127 files
No security note in commit
Low 35 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

disable the sign button in the sign message dialog while an encrypted wallet is decrypting

This commit fixes a user-interface timing issue in Sparrow Wallet's 'Sign Message' feature. When a user tried to sign a message with an encrypted wallet, the 'Sign' button stayed active while the wallet was still decrypting in the backgrou…

UI race condition between user action and background decryptionRepeated sign button clicks possible during asynchronous wallet decryptionPotential double-signing or inconsistent dialog state
31de9cbcby Craig Raw+11−11 file
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Bump version and dependencies

This commit is a routine version bump for the BTCPay Server application and updates several third-party software libraries and build tools to newer patch versions. There is no indication in the commit itself that this is a security fix, an…

415625c1by Nicolas Dorier+11−119 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →