Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24273Commits captured
20891AI analyses
58High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20891 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 35 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Update translation strings

This commit only updates translation strings in a localization file and removes a trailing newline from a Swagger JSON file. There are no code behavior changes, no security fixes, and no functional modifications.

fbcfbc8eby Nicolas Dorier+67−322 files
No security note in commit
Informational 12 AI analysisMessage 58 · Thin
EL ElectrumElectrum BitcoinSoftware wallets

Merge pull request #10993 from spesmilo/remove_attr

This commit replaces the third-party 'attrs' library with Python's built-in 'dataclasses' across several Electrum source files. It is a routine refactoring change: the same data classes are defined in a different syntax, and equivalent val…

4cb03ef4by ghost43+195−1248 files
No security note in commit
Moderate 51 AI analysisMessage 73 · Adequate
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Merge pull request #7612 from minmoto/okjodom/store-credentials-permission

This change introduces a new, more specific permission called 'Manage access tokens' for store-level access token operations in BTCPay Server. Previously, viewing tokens required the broad 'View store settings' permission and creating or r…

New fine-grained authorization policy introduced for sensitive credential-management operationsController actions and views switched from CanViewStoreSettings/CanModifyStoreSettings to CanManageStoreCredentialsMigration auto-grants new permission to the built-in Manager role to preserve expected access
a0319215by Nicolas Dorier+101−2010 files
No security note in commit
Low 25 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6955: key_expression: preserve master-key invariants in Xpub Arbitrary

This change fixes a bug in test-only code that generates random fake Bitcoin extended public keys (xpubs). Previously, when generating a master xpub (depth 0), the code could pick random values for the parent fingerprint and child number, …

BIP32 master-key invariant violation in generated test dataEncode/decode round-trip failure for generated master xpubsFix aligns Xpub::arbitrary with existing Xpriv::arbitrary behavior
4116ecc6by Andrew Poelstra+35−31 file
No security note in commit
Moderate 60 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35833: log: prevent user input from injecting fake log lines

This update fixes a way that people with limited access to a Bitcoin node could make fake log entries appear real. Normally, the node cleans up special characters in log messages but was leaving newlines alone. A clever user could slip a n…

Log injection / log forgery via embedded newlines in untrusted inputInput from restricted RPC users reaching log output without newline escapingControl-character escaping bypass due to explicit newline exception
d4b0e1e4by Ava Chow+48−114 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 60 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8192: rename the test doubles to Mock*, matching the rest of the suite

This commit only renames test helper classes from 'Fake*' to 'Mock*' in a single unit test file. It makes no functional changes to the firmware or to any real security behavior. There is no security issue here.

cf55b2e5by Jack+7−71 file
No security note in commit
Moderate 61 AI analysisMessage 75 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge remote-tracking branch 'origin/dev-v2.4.0' into taproot-bip322-message-signing

This merge commit pulls in several defensive fixes for the Passport hardware wallet. The most important changes reduce the maximum passphrase length from 1000 to 256 characters so passphrases are not silently truncated when deriving a wall…

Passphrase length capped to match KDF input limit, preventing silent truncation of BIP39 passphrasesBackup restore now refuses to restore wallet identity metadata (xfp, xpub, root_xfp) from backup and re-derives it from the restored secretMissing comma in error-code tuple fixed; the bug had caused two error names to merge into one and become unreachable
d8086007by Jack+416−1811 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 78 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8192: rename Fake* test doubles to Mock*

This commit only renames test helper classes from 'Fake*' to 'Mock*' across seven test files. It does not change any actual product code or test behavior, so it has no security relevance on its own.

f05921e1by Jack+116−1167 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

Signed for mk release.

This commit only updates the release signature file. It adds two new cryptographic hashes for recently built firmware files and refreshes the PGP signature that covers the whole file. There are no code changes, no bug fixes, and no securit…

5dbb374bby Peter D. Gray+10−81 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

update block height

This commit simply updates an automatically-generated Bitcoin blockchain checkpoint number in a single file. It changes one digit in the stored block height and the timestamp by less than two minutes. There is no security relevance.

d3db2a30by Peter D. Gray+2−21 file
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →