Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24358Commits captured
20927AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20927 analyses
Highest risk·RSS
Informational 20 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36233: guix: Update time-machine to `60f6956aeffa7f30285745bd0ea615e9acfc74f8`

This is a build-system maintenance update for Bitcoin Core's reproducible build environment (Guix). It updates the Guix time-machine commit and several dependency versions, and temporarily disables some test suites that fail when building …

No direct security-relevant code change in Bitcoin Core consensus, wallet, or P2P layers.Dependency version bumps (git-minimal, linux-headers, python-lief, python-minimal) are routine build-environment updates.Disabling third-party package test suites reduces build-time test coverage but does not alter Bitcoin Core's own test or release binaries.
619185d5by merge-script+32−73 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(translations): sync Crowdin translations

This commit is a routine synchronization of translated user-interface text strings from the Crowdin translation platform. It only changes wording, grammar, capitalization, and missing translations in JSON files for several languages. There…

f312dca2by Thalarion+301−3217 files
No security note in commit
Low 33 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #685 from Foundation-Devices/fix/errors-enum-missing-comma

This commit adds a regression test to make sure two specific error codes (NOT_BIP39_MODE and MULTISIG_STORAGE_IDX_ERROR) actually exist in the firmware's error list. The underlying bug was a missing comma in a tuple of error names, which s…

Regression test added for enum member integrityMissing comma in string tuple could silently remove error codesRuntime AttributeError risk when removed error codes are referenced
670c3886by Jacksper13+23−02 files
No security note in commit
Informational 15 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

test(clear_signing): add binaries for external device test

This commit only adds test data files for Ethereum clear-signing tests. It includes a token definition for DAI on Ethereum mainnet and a fake network/token definition for chain ID 223, plus updates to UI test fixtures. There is no change t…

7867262dby PrisionMike+883−7424 files
No security note in commit
Moderate 59 AI analysisMessage 83 · Strong
SS SeedSignerSeedSigner BitcoinHardware wallets

Narrow bare p2sh candidacy to what the rebuild cannot decide

This commit fixes a logic flaw in how SeedSigner decides whether a Bitcoin transaction output is 'change' going back to the user's own wallet, versus a payment to someone else. Previously, a specially crafted PSBT could make an output that…

PSBT output ownership misclassificationFingerprint vs key derivation mismatch in change detectionContradiction between supplied derivation path and redeem script omission
f04675e4by kdmukai+70−82 files
No security note in commit
Low 26 AI analysisMessage 58 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8161: honour USE_BIP39_GENERATE

This commit removes an unused function called `trezorcrypto.bip39.generate()` from the firmware's exposed programming interface. The function was supposed to be disabled by a build flag (`USE_BIP39_GENERATE=0`) but the flag was being ignor…

Build flag was not being honored, leaving an unused cryptographic API exposedChange reduces firmware API surface by removing a seed-generation bindingRegression test added to prevent accidental re-exposure
94ec6c40by Jack+50−04 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8162: validate and confirm a developer pubkey before installing it

This commit fixes a security gap in the Passport hardware wallet's developer-public-key installation flow. Previously, the device only checked that the key file was 88 bytes long and installed whatever 64-byte blob it found without showing…

Input validation added for cryptographic public key before secure-element writeUser confirmation prompt added before trusting a developer firmware signing keyAll-zero key explicitly rejected in the install flow
dded7d41by Jack+129−164 files
Vendor flagged security relevance
Moderate 59 AI analysisMessage 78 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8167 SFT-8168: validate sighash types per input type

This commit tightens how a Bitcoin hardware wallet (Passport) checks the 'sighash' flag for each transaction input. Previously the same allowed list was used for every input type, which meant a non-taproot input could in principle be asked…

Input-type-specific sighash validationRemoval of shared VALID_SIGHASHES check that allowed SIGHASH_DEFAULT on non-taproot inputsLegacy preimage now commits to actual sighash_type instead of constant 0x01
3286a7d9by Jack+364−134 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8171: bounds accounting in BIP39 prefix matching

This commit fixes a buffer-size accounting bug in the Passport hardware wallet's BIP39 word lookup feature. The function that returns matching seed-phrase words could write slightly past the end of its output buffer in some edge cases, and…

Off-by-one / separator accounting error in buffer fillingSigned-to-unsigned conversion of user-supplied count in language bindingPotential buffer over-write in BIP39/bytewords prefix helper
fd77dd1eby Jack+115−114 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36364: tools: Call SHA256AutoDetect in bitcoin-util, bitcoin-tx and bitcoin-wallet

This change makes three Bitcoin command-line tools (bitcoin-tx, bitcoin-util, and bitcoin-wallet) automatically pick the fastest SHA-256 hashing implementation available on the computer, such as hardware-accelerated versions on modern CPUs…

dc2a9987by merge-script+6−03 files
No security note in commit
Informational 19 AI analysisMessage 83 · Strong
LD LedgerLedger Bitcoin app BitcoinHardware wallets

python client: first-class PSBT_GLOBAL_GENERIC_SIGNED_MESSAGE field

This commit adds support in Ledger's Python Bitcoin client for a new PSBT global field used by BIP-322 generic signed messages. It is a feature addition: parsing, serialization, and round-trip tests for the new field. There is no indicatio…

No security-relevant signals presentFeature addition for BIP-322 PSBT field supportIncludes input-validation tests (duplicate key rejection, keydata rejection)
60573e28by Salvatore Ingala+83−24 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →