Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24364Commits captured
20929AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20929 analyses
Highest risk·RSS
Moderate 57 AI analysisMessage 81 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Merge PR 'Don't track refused monitor updates as pending' (#5030)

This patch fixes a bookkeeping bug in rust-lightning's ChainMonitor. When a channel monitor refuses an update (for example, because the channel is already force-closing), the code used to still record that update as 'pending completion.' B…

State inconsistency: pending monitor updates tracked for updates that will never completePotential denial of service / channel freeze: stale pending entry could block completion actionsLightning-specific risk: delayed or blocked PaymentClaimed event could affect fund recovery timing
47850384by Matt Corallo+44−132 files
No security note in commit
Informational 17 AI analysisMessage 68 · Adequate
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'desktop-ui' into brightness-fix

This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…

Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
2932c7e0by Keeqler+3592−143843 files
No security note in commit
Informational 15 AI analysisMessage 77 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(translations): Shorten provider contract address for french string

This commit simply shortens a French translation string on Trezor hardware wallets. The phrase 'Provider contract address' is changed to just 'Contract address' in French, and the translation signature file is updated accordingly. There is…

7c4107bcby PrisionMike+4−42 files
No security note in commit
Low 45 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11364

This tiny change adjusts how the Monero wallet treats old-style unencrypted payment IDs when it cannot determine the block version of the transaction. Previously, if the block version was unknown (reported as 0), the wallet would still pro…

Privacy-hardening change: long payment IDs are unencrypted and can link transactions/addressesUnknown block version now defaults to ignoring long PIDs rather than accepting themSingle-line logic fix with no input validation, crypto, or memory-safety changes
2f9d1bbbby tobtoht+1−11 file
No security note in commit
Moderate 63 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11371

This Monero update tightens how the network handles trimmed-down (pruned) transaction data shared between nodes. Before, a node could accept extra junk bytes tacked onto the end of a pruned transaction blob. Now it rejects such blobs. This…

New strictness check on pruned transaction blob parsingRejection of trailing data after serialized transaction baseProtocol-level input validation change
e4979244by tobtoht+4−33 files
No security note in commit
Informational 19 AI analysisMessage 66 · Adequate
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11368

This commit fixes a wallet-creation bug: when restoring a Monero wallet from a special newer-style seed (called a Polyseed) using a JSON configuration file, the wallet software previously treated it like an older Electrum-style seed. This …

Incorrect key derivation path for Polyseed when a seed passphrase is supplied via JSONRestore height mishandling causing wallet to scan from wrong block heightFunctional test added to assert correct Polyseed address, birthday, and encryption flag
b5ab65c3by tobtoht+40−114 files
No security note in commit
Informational 23 AI analysisMessage 66 · Adequate
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11365

This commit adds a new read-only wallet command called get_wallet_info that lets an authenticated user ask the wallet for basic metadata such as the wallet file name, address, wallet type, which network it is on, the daemon address, and an…

New RPC endpoint exposes wallet metadata including daemon address and proxy configurationEndpoint is denied in restricted RPC mode, reducing exposure for shared/public RPC setupsProxy state consistency fix removes stale m_proxy value after set_daemon/set_proxy calls
74ab3773by tobtoht+111−27 files
No security note in commit
Low 46 AI analysisMessage 66 · Adequate
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11007

This Monero update improves how nodes download and queue blocks during blockchain synchronization. It changes the way pruned block sizes are counted, adds a check that pruned block weights match known values, and switches the download queu…

Replaced simple zero-weight check with cryptographic-weight validation against prevalidated chain dataAdded overflow/underflow guards in sync-size arithmetic (division instead of multiplication, NaN/inf checks)Changed queue limit from span-based to block-count-based with dynamic recalculation
9314ec5dby tobtoht+172−5710 files
No security note in commit
Low 34 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11373

This change removes the 'strip unassigned code points' option from two Unicode text normalization functions used when handling Polyseed mnemonic seed phrases. Previously, characters that Unicode has not officially assigned any meaning to w…

Behavioral change in key-derivation input normalizationRemoval of silent stripping of unassigned Unicode code pointsPotential for same mnemonic input to produce different wallet keys before/after patch
9401067cby tobtoht+2−21 file
No security note in commit
Low 46 AI analysisMessage 63 · Adequate
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11369

This Monero commit changes how sensitive random-number and hash-key setup is performed. Previously, some initialization code could run automatically during program startup in a way that wasn't guaranteed to be thread-safe, and the secret S…

Static initialization order fiasco mitigationThread-safe one-shot initialization for RNG stateSipHash key no longer exposed as writable global array
3b7d8421by tobtoht+62−105 files
No security note in commit
Informational 15 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11374

This commit only fixes spelling mistakes in code comments and documentation strings. No actual program logic, math formulas, or executable code was changed. It cannot affect security in any way.

7a50b92cby tobtoht+4−42 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →