Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24358Commits captured
20927AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20927 analyses
Highest risk·RSS
Moderate 60 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-981: expose HDNode.blank() again and call it where it was commented out

This commit fixes a security hygiene issue in the Passport hardware wallet firmware where sensitive cryptographic key material (HD wallet nodes and a BIP39 master seed) was not being actively wiped from device memory when no longer needed.…

Restoration of explicit sensitive-data wiping (HDNode.blank)Replacement of no-op blank_object() HDNode branch with actual wipeAddition of finalizer to deserialized HDNode to ensure heap wipe on collection
82f73907by Jack+93−65 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core/bolt): allow back in multishare setup

This commit is a user-interface feature change for Trezor hardware wallets. It adds an on-screen 'back' arrow during multi-share backup setup so users can return to a previous step, and moves the 'More info' help into a menu button. There …

42d13264by obrusvit+348−5110 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8169: remove dead witness iterator branch and reject witness serialized unsigned txns clearly

This commit cleans up how the Passport hardware wallet handles Bitcoin transactions that incorrectly include witness data. It removes a dead, broken code branch that referenced non-existent variables and replaces a confusing low-level erro…

Removes unreachable branch referencing undefined variables (`fd`, `num_in`), eliminating a latent crash or confusion riskReplaces a bare ValueError with a structured FatalPSBTIssue, improving error handling and user messagingMaintains existing rejection policy for BIP-174 non-compliant PSBTs (no validation relaxation)
f2be0575by Jack+112−323 files
No security note in commit
Informational 23 AI analysisMessage 98 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36321: net: cast vector size to avoid overflow, truncation, sign change

This is a one-line fix in Bitcoin Core's network code. It changes how the size of a list of block headers is converted to a signed integer inside a loop. Previously, if the list was empty, the conversion could trigger undefined-behavior wa…

UndefinedBehaviorSanitizer integer sanitizer warning addressedImplicit signed/unsigned conversion in loop counterUnsigned integer wraparound on empty vector size
ced4c6e6by merge-script+1−11 file
No security note in commit
Moderate 63 AI analysisMessage 50 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8173: validate scalar and point buffer lengths in the ECDSA bindings

This commit fixes a buffer length bug in the firmware's cryptographic code. Two functions that perform elliptic-curve math were reading exactly 32 bytes from caller-supplied buffers without first checking that the buffers were actually 32 …

Out-of-bounds read in cryptographic binding (C extension reading fixed 32 bytes without validating buffer length)Potential information disclosure or fault/crash from malformed scalar or point buffersMissing input validation in ECDSA low-level primitives exposed to Python
78ab7429by Jacksper13+86−03 files
No security note in commit
Informational 15 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(ethereum): reword contract address label.

This commit only rewords user-facing labels in the Trezor Ethereum user interface. It replaces the term 'Provider contract address' with 'Contract address' and removes the separate 'Interaction contract' label, using one consistent label a…

7ed8ff9bby PrisionMike+5099−513515 files
No security note in commit
Low 44 AI analysisMessage 73 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

Merge pull request #11003 from SomberNight/202609_tx_any_segwit

This commit renames Electrum's transaction 'is_segwit' check to 'is_any_segwit' and adds a new 'is_all_segwit' check. It then uses the stricter 'all inputs are segwit' rule when validating Lightning channel funding transactions and timeloc…

Renamed ambiguous 'is_segwit' to 'is_any_segwit' and introduced stricter 'is_all_segwit'Funding transaction validation in Lightning channel establishment now requires all inputs to be segwit (non-malleable txid)Timelock recovery plugin now asserts all inputs are segwit for alert/recovery/cancellation transactions
ede66c89by ThomasV+86−704 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Add maintainer doc

This commit adds a single sentence to an internal maintainer documentation file, instructing maintainers to also update a separate documentation repository when changing documentation structure. It does not modify any code, configuration, …

69c44f1eby Nicolas Dorier+2−01 file
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
EP Elements ProjectCore Lightning BitcoinLightning Network

connectd: keep the subd fd until connectd has received it

This commit fixes a macOS-specific bug where opening a Lightning channel could fail or hang with 'Peer connection lost'. The root cause was a race condition in how file descriptors (sockets) were passed between internal processes: the send…

Race condition in inter-process file descriptor passing (SCM_RIGHTS)Availability impact: fundchannel failure/hang under load on macOSNo evidence of confidentiality or integrity compromise
5e19c704by dovgopoly+65−5310 files
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Organize maintainer documentation

This commit only reorganizes the project's internal maintainer documentation. It splits one large README into smaller files (coding conventions, local development, Greenfield API) and updates links in related docs and agent skill files. No…

6c74356fby Nicolas Dorier+337−18812 files
No security note in commit
High 70 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6919: Sanitize serde size hints before allocating

This commit fixes a denial-of-service weakness in how the library deserializes lists of Bitcoin data (witnesses, amounts, fee rates) from untrusted input. Before the fix, a few bytes of attacker-controlled data could claim a list would con…

Untrusted serde size hint fed directly into Vec::with_capacityPotential memory exhaustion / OOM kill from small malicious inputDenial-of-service vector in deserialization paths
55ddbc0cby Andrew Poelstra+88−105 files
Vendor flagged security relevance
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →