Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24352Commits captured
20923AI analyses
58High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20923 analyses
Highest risk·RSS
Informational 15 AI analysisMessage 30 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

Temporary Seed Names does not fit as menu item on Mk4 & Mk5

This commit shortens a menu label on older COLDCARD devices (Mk4 and Mk5) because the original text 'Temporary Seed Names' was too long to display on their smaller screens. It is a user-interface fix with no security relevance.

7243a6ddby scgbckbone+14−42 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core/delizia): passphrase prompt marquee

This commit is a user-interface polish fix for the Trezor hardware wallet's passphrase entry screen. It replaces a static text label with a scrolling 'marquee' so that longer prompts fit on the small device screen. There is no security-rel…

72b73928by obrusvit+77−282 files
No security note in commit
Moderate 59 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

bip39: avoid unwiped mnemonic copies

This commit fixes a security hygiene issue in the BitBox02 hardware wallet's handling of BIP39 recovery phrases (mnemonics). When converting a mnemonic to text, the previous code could create temporary copies of the secret phrase in memory…

Sensitive data (BIP39 mnemonic) may have been left in memory due to string reallocation/growthUse of `zeroize::Zeroizing` to attempt secure erasure of secret materialPre-allocation of fixed capacity to avoid heap reallocations during secret serialization
f68abb80by Cedric Wiese+22−52 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

test(clear_signing): use jsons for testing external defintions

This commit only changes test code. It switches the way Trezor's automated tests store and load Ethereum 'clear signing' definitions from pre-generated binary files to plain JSON files that are converted and signed on the fly during tests.…

7bd70549by PrisionMike+103−313 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6947: build(deps): bump cargo-bins/cargo-binstall from 1.21.0 to 1.21.1

This commit updates the version of a helper tool (cargo-binstall) used only inside GitHub Actions automation. It is a routine dependency bump by Dependabot and does not change any code that ships to users. There is no indication of a secur…

c1be49cbby Andrew Poelstra+2−22 files
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36377: doc: add 461 (Deterministic ECDSA signatures with low-R grinding) to bips.md

This commit is a documentation-only update. It adds a single line to Bitcoin Core's list of implemented BIPs, noting that BIP 461 (a technique for making ECDSA signatures smaller and deterministic) has been implemented since version 0.17.0…

e0f16ef9by merge-script+1−01 file
No security note in commit
Informational 15 AI analysisMessage 87 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(tests,definitions): switch from .dat to .json

This commit is a routine maintenance change in the Trezor firmware repository. It converts Ethereum test fixture files from a binary .dat format to a human-readable .json format. The actual content of the definitions (token names, contract…

85e91e74by PrisionMike+3802−0160 files
No security note in commit
Informational 15 AI analysisMessage 87 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

test(clear_signing): move .dat files to json fixtures directory

This commit only moves existing test data files (.dat files used for Ethereum clear-signing tests) from one directory to another inside the test fixtures area. No code, firmware logic, or user-facing behavior was changed. It is purely a ho…

a81c9975by PrisionMike+0−081 files
No security note in commit
Moderate 51 AI analysisMessage 68 · Adequate
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Add store permission for managing access tokens

This change adds a new, more specific permission for managing store access tokens in BTCPay Server. Previously, viewing or managing these tokens required only broad 'view store settings' or 'modify store settings' permissions, which meant …

Authorization boundary tightening: lower-privileged store roles (e.g., Guest) lose access to token management UI/actionsNew granular permission reduces blast radius of 'modify store settings' permissionDatabase migration retroactively grants new permission to existing Manager role
0ea1d8deby okjodom+101−2010 files
No security note in commit
High 71 AI analysisMessage 81 · Strong
LWS Monero LWSMonero LWS Indexing infrastructureMoneroPrivacy protocols

Fixes for issues reported by llm (#297)

This commit fixes nine separate bugs in the Monero Light Wallet Server (LWS). The most serious ones are: an infinite loop when importing certain address data, a missing size limit that let unauthenticated remote clients request huge amount…

Infinite loop in database import path (DoS)Missing authentication-time message size limit on remote scanner protocol (memory exhaustion / DoS)Untrusted array reads from client in light wallet RPC
81451fb2by Lee *!* Clagett+62−129 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 58 · Thin
LL Lightning LabsLND BitcoinLightning Network

Merge pull request #11281 from ziggie1984/lint-intrange-cleanup

This commit is a large but purely cosmetic code cleanup. It replaces old-style Go for loops like 'for i := 0; i < N; i++' with the newer 'for i := range N' syntax introduced in Go 1.22. No logic, behavior, or security properties of the cod…

95c56eebby Olaoluwa Osuntokun+144−14449 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →