Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24352Commits captured
20923AI analyses
58High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20923 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 68 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Revert "ChainMonitor::_entropy_source -> ::entropy_source"

This commit simply renames a field inside the ChainMonitor struct from `entropy_source` back to `_entropy_source`. The leading underscore is a Rust convention meaning 'this field is intentionally unused.' The commit message explains the fi…

e0c0bcddby Valentine Wallace+12−121 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

update block height

This commit simply increments a stored Bitcoin blockchain height value by one block (from 969,311 to 969,312) and updates the corresponding timestamp by 97 seconds. It is an auto-generated data update with no code logic changes and no appa…

54a7fafaby Peter D. Gray+2−21 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

update block height

This is a routine data update that bumps an internal Bitcoin block height number used by the COLDCARD firmware. There are no code logic changes, no bug fixes, and no security-relevant behavior changes visible in the diff.

df07ca73by Peter D. Gray+2−21 file
No security note in commit
Informational 15 AI analysisMessage 93 · Strong
BC Bitcoin Corelibsecp256k1 BitcoinCryptographic libraries

Merge bitcoin-core/secp256k1#1949: ecdsa: Clarify derivation of the r check in `_sig_verify`

This commit only rewrites comments in the source code to make the mathematical explanation clearer. It does not change any actual code instructions, function behavior, or security properties. There is no vulnerability or fix here.

4a264a93by merge-script+21−151 file
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36391: test: fix typo in rpc_psbt

This commit fixes a one-word typo in a comment inside a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually calls 'walletcreatefundedpsbt'. No code behavior changes, and there is no sec…

4b612c6bby merge-script+1−11 file
No security note in commit
Informational 12 AI analysisMessage 100 · Strong
BC Bitcoin Corelibsecp256k1 BitcoinCryptographic libraries

Merge bitcoin-core/secp256k1#1948: tests: add ECDSA verify case where r + n overflows p

This commit only adds a new test case to the project's test suite. It does not change any production cryptographic code. The new test verifies that the ECDSA signature verification function correctly rejects a crafted invalid signature in …

Adds test coverage for ECDSA verification edge case involving r + n overflow against field order pReferences a surviving mutant where the early-rejection check in secp256k1_ecdsa_sig_verify is removedDoes not modify production code; purely a test-suite enhancement
e23e9201by merge-script+28−01 file
No security note in commit
Informational 15 AI analysisMessage 82 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

test: fix typo in rpc_psbt

This commit fixes a typo in a comment within a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually exercises 'walletcreatefundedpsbt'. No code behavior changes, and there is no security…

0a8ffe90by Bruno Garcia+1−11 file
No security note in commit
Informational 24 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(ethereum): Remove hardcoded names for registry known addresses

This commit removes a long list of hardcoded friendly names (like 'Lido', 'Morpho', 'WalletConnect') that Trezor devices previously showed when signing Ethereum transactions to certain smart contracts. After the change, only a few built-in…

Removal of hardcoded trust labels reduces attack surface for label-spoofing or stale-name confusionUser-visible display changes from friendly names to raw addresses for many DeFi contractsNo cryptographic, parsing, or memory-safety changes in the diff
5f1c1003by PrisionMike+22−1304 files
No security note in commit
Moderate 60 AI analysisMessage 78 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

Merge pull request #10874 from spesmilo/plugin_zipfile

This commit hardens how Electrum loads third-party plugins. Previously, the app could authorize a plugin zip file, then later re-read that same file from disk to run it. An attacker who could replace the file in the brief gap (a 'time-of-c…

Fixes time-of-check/time-of-use (TOCTOU) race between plugin signature verification and disk-based module loadingIntroduces in-memory zip importer to prevent on-disk substitution after authorizationAdds hash verification (sha256) before loading plugin code or reading plugin resources
aa630dd6by Felix+658−855 files
Vendor flagged security relevance
Informational 20 AI analysisMessage 60 · Adequate
BC Bitcoin Corelibsecp256k1 BitcoinCryptographic libraries

tests: add ECDSA verify case where r + n overflows p

This commit adds a new test case to the secp256k1 cryptographic library's test suite. It checks that ECDSA signature verification correctly rejects a crafted edge case where a mathematical value (r + n) overflows the prime field boundary. …

ECDSA signature verification edge-case testr + n overflow modulo p boundary conditionRegression test only; no functional code change
fc88acc3by ViniciusCestarii+28−01 file
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →