Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24363Commits captured
20928AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20928 analyses
Highest risk·RSS
Low 47 AI analysisMessage 50 · Thin
FD FoundationPassport firmware BitcoinHardware wallets

SFT-8184: restore the NOT_BIP39_MODE and MULTISIG_STORAGE_IDX_ERROR error codes

This commit fixes a simple but consequential typo in a list of error names: a missing comma had caused two distinct error codes to be merged into one long, meaningless name. As a result, any code that tried to use either of the two intende…

Missing comma in a Python tuple silently merged two error-code identifiersRuntime AttributeError would occur on any path referencing the two intended error codesAffected codes relate to multisig storage index handling and BIP39 seed mode enforcement
0b7c5a05by Jacksper13+24−13 files
No security note in commit
Informational 18 AI analysisMessage 80 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core/caesar): allow back in multishare setup

This commit adds a 'go back' navigation feature to the backup setup screens on Trezor's older 'Caesar' device layout. It lets users step backward through the multi-share backup checklist and number-selection carousels, matching behavior al…

No memory-safety changesNo cryptographic changesNo input validation changes
ce193b55by obrusvit+282−368 files
No security note in commit
Informational 18 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

replace the qr display density toggle with low, medium and high levels that produce the same qr code version for ur and bbqr

This commit changes how Sparrow Wallet lets users pick QR code density when displaying animated QR codes. It replaces a two-option toggle (Normal/Low) with three levels (Low/Medium/High) and makes sure both supported QR formats (UR and BBQ…

344895b3by Craig Raw+98−304 files
No security note in commit
Informational 15 AI analysisMessage 62 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(clear_signing): show chain name or number in all flows

This commit is a user-interface improvement for Trezor hardware wallets when approving Ethereum transactions. It makes sure the wallet always shows which blockchain network (for example Ethereum mainnet, Polygon, or an unknown chain ID) is…

7c586094by PrisionMike+52−236 files
No security note in commit
Informational 12 AI analysisMessage 100 · Strong
BC Bitcoin Corelibsecp256k1 BitcoinCryptographic libraries

Merge bitcoin-core/secp256k1#1947: musig: test nonce_gen_counter with random counters

This commit only adds a new test to the MuSig cryptographic module. It does not change any production code. The new test verifies that two different nonce-generation functions produce matching results when given equivalent random 64-bit co…

MuSig nonce generation is security-critical; nonce reuse can leak private keys.The PR description discusses a mutation that could enable nonce reuse, but the mutation is not in the committed code.The change is test-only; no production cryptographic logic is altered.
2b4a7b90by merge-script+24−01 file
No security note in commit
Informational 20 AI analysisMessage 60 · Adequate
BS BlockstreamBlockstream Jade BitcoinHardware wallets

auth: add unattended pin selection for rpc tests

This commit adds a debug-only feature that lets automated tests set or change the device's PIN over an internal RPC message. It only compiles when special debug flags are enabled and is not present in normal production firmware. The change…

New RPC endpoint debug_set_pin can set/change the unlock PINPIN-handling code path modified to read from a mutable debug context instead of a fixed constantCode is wrapped in CONFIG_DEBUG_UNATTENDED_CI and CONFIG_DEBUG_MODE preprocessor guards
309ee8bbby Mike Tolkachev+100−205 files
No security note in commit
Informational 15 AI analysisMessage 68 · Adequate
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Use canonical documentation links (#7607)

This commit only updates web links and documentation references throughout the BTCPay Server project. It points users to newer, canonical documentation URLs and refreshes local development instructions. There are no code behavior changes, …

677a7f34by Nicolas Dorier+34−1712 files
No security note in commit
Informational 15 AI analysisMessage 73 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge remote-tracking branch 'origin/send-wallet-core' into brightness-fix

This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.

1f4209d3by Keeqler+77−10512 files
No security note in commit
Moderate 60 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

This commit fixes how the Rust Bitcoin library calculates old-style (legacy) transaction signatures when the spending script contains a special opcode called OP_CODESEPARATOR. Previously the library did not handle this opcode at all, which…

Protocol correctness fix for legacy sighash serializationOP_CODESEPARATOR handling added to match Bitcoin Core consensus behaviorPreviously omitted test vectors restored, indicating prior non-compliance
5b815281by Andrew Poelstra+600−3093 files
No security note in commit
Informational 15 AI analysisMessage 96 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6948: build(deps): bump taiki-e/install-action from 2.83.2 to 2.85.4

This is a routine update by Dependabot to the version of a third-party GitHub Action used in the project's automated testing workflows. The change only affects internal continuous integration (CI) scripts, not the actual Bitcoin library co…

d1431904by Andrew Poelstra+2−22 files
No security note in commit
Informational 23 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #173 from MAGICGrants/review-prompt

This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…

Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
6528c1cbby Keeqler+165−19 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →