Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24364Commits captured
20929AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20929 analyses
Highest risk·RSS
Low 44 AI analysisMessage 45 · Thin
EL ElectrumElectrum BitcoinSoftware wallets

transaction: add method tx.is_all_segwit()

This commit adds a helper method to check whether every input of a Bitcoin transaction uses SegWit, and starts using it in place of a weaker 'any input is SegWit' check when validating Lightning funding transactions. SegWit fixes 'transact…

Replaced weaker malleability check with stronger all-inputs SegWit check in Lightning funding transaction validationCode comment explicitly tied the change to transaction malleability and funding txid stabilityPrior code contained a '# FIXME needs is_all_segwit' indicating the old check was known to be insufficient
43bb00d4by SomberNight+20−63 files
Vendor flagged security relevance
Low 27 AI analysisMessage 65 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

transaction: rename tx.is_segwit() to tx.is_any_segwit()

This commit is a code cleanup that renames a method from is_segwit() to is_any_segwit() and adds a clarifying comment. It does not change the actual behavior of the code. The rename makes it clearer that the method returns true if any inpu…

Rename-only refactor of SegWit detection methodAdded FIXME in Lightning channel funding flow noting current check uses 'any' semantics where 'all' may be desiredAdded comment explaining residual malleability of non-SegWit inputs in a partially SegWit transaction
94a400faby SomberNight+67−653 files
No security note in commit
Informational 15 AI analysisMessage 0 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Update docs

This commit is a one-line documentation update. It adds a hyperlink to the interactive authorization flow in the developer API guide. There is no code change, no security fix, and no functional change to the software.

bc3d8ee4by Nicolas Dorier+1−11 file
No security note in commit
Informational 19 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

feat(core): allow back in multishare setup

This commit changes the on-device backup setup flow for newer Trezor devices so users can go back and revise choices such as the number of shares or the threshold. It is a user-experience improvement, not a security fix. The code removes t…

No security-relevant signal: change is a UX flow refactor for backup setup.Removal of cancel/ActionCancelled path on some screens in favor of Back navigation.New state machine assertions guard that share_count, group_threshold, and groups are populated before use.
486cd24aby obrusvit+632−9616 files
No security note in commit
Moderate 59 AI analysisMessage 73 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

Merge pull request #10984 from f321x/fix_onchain_backup_discovery

This commit fixes how Electrum's Lightning wallet discovers and watches 'on-chain channel backups'—recovery records embedded in funding transactions. Previously, backups could be missed if the wallet learned about a transaction in stages, …

Loss of funds due to missed channel backup discoveryWatcher callback collision when funding address is reusedInsufficient replay protection for on-chain backup OP_RETURN data
670b16a7by ghost43+117−359 files
No security note in commit
Informational 15 AI analysisMessage 18 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

version bump

This commit is a routine version bump for the COLDCARD firmware release process. It updates version strings in two build makefiles (from 5.6.2 to 5.6.3 for Mk, and from 1.5.2Q to 1.5.3Q for Q) and finalizes the release date and changelog e…

97719c6bby Peter D. Gray+11−113 files
No security note in commit
Low 39 AI analysisMessage 73 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

Merge pull request #11000 from f321x/bip32_index_with_whitespace

This commit tightens how Electrum parses BIP32 wallet derivation paths. Previously, the code used Python's built-in int() conversion, which accepts a wide variety of number-like strings, including whitespace, plus signs, underscores, and n…

Input validation hardening for BIP32 derivation path parsingRemoval of permissive int() parsing that accepted whitespace, plus signs, underscores, and non-ASCII digitsPrevention of ambiguous or surprising path index interpretation
3462e02bby ghost43+16−52 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Organize documentation by audience (#7598)

This commit is a large documentation reorganization for BTCPay Server. It moves existing guidance into audience-specific folders (users, operators, developers, maintainers), adds new guides for plugins and API integrations, updates links t…

b14e58faby Nicolas Dorier+2176−62742 files
No security note in commit
High 78 AI analysisMessage 50 · Thin
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

Restrict signing and Teleport retry QR scans to expected types

This update fixes a bug in the COLDCARD Q1 hardware wallet where scanning a QR code from the 'Ready To Sign' or 'Key Teleport retry' screens could accidentally replace the device's master seed with seed words or an extended private key sho…

Unintended master seed replacement via QR scan in signing/Teleport flowsMissing input-type validation on context-sensitive QR scannerTightened secure-element secret-overwrite guard in set_seed_value()
fcc0dc96by scgbckbone+70−87 files
Vendor flagged security relevance
Low 37 AI analysisMessage 45 · Thin
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

Warn before risky firmware upgrades

This commit adds user-facing warnings to the COLDCARD hardware wallet before it installs firmware that is either signed by someone other than Coinkite (an 'external contributor') or older than the firmware already on the device (a downgrad…

Adds explicit user warning for externally signed firmware imagesAdds explicit user warning for firmware downgradesDoes not enforce a hard block; relies on user consent
5c13be46by scgbckbone+77−43 files
Vendor flagged security relevance
Informational 12 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove events no longer posted along with their subscribers

This commit removes several unused event classes and their corresponding event listeners from the Sparrow Wallet codebase. It is a cleanup change: the events were no longer being posted anywhere, so the code that subscribed to them was dea…

ee2daf94by Craig Raw+0−14611 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →