Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24364Commits captured
20929AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20929 analyses
Highest risk·RSS
Low 37 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

remove the terminal saving and loading dialogs and show an error when saving a new wallet or opening a wallet fails

This commit fixes several small but real bugs in Sparrow Wallet's terminal (command-line) interface. It prevents the app from crashing with a NullPointerException when an error message is missing, makes sure password memory is wiped even w…

NullPointerException avoided on exception message handlingPassword SecureString now cleared on both success and failure pathsTerminal loading/saving dialogs no longer remain open after errors
78025f22by Craig Raw+11−43 files
No security note in commit
Low 30 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

show an error when a scanned ur of type bytes is not a psbt, transaction or utf-8 text

This commit fixes a small bug in Sparrow Wallet's QR code scanner. Previously, when a scanned QR code contained raw bytes that could not be recognized as a PSBT, transaction, or readable text, the scanner would create an error message but …

Error-handling path failed to return error result, leading to silent null returnFix changes assignment to immediate return of URException resultNo cryptographic, parsing-safety, or trust-boundary changes observed
d326df88by Craig Raw+1−31 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge branch 'nickez/make-config-attempt2'

This is a large build-system refactor for the BitBox02/BitBox03 firmware repository. It replaces hard-coded Make targets and CMake-generated J-Link scripts with a new Python-based configuration system that lets developers choose product, e…

2008ca11by Niklas Dusenlund+932−57028 files
No security note in commit
Informational 23 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

compare rewritten keystore derivation paths when checking for a single derivation path in the terminal receive dialog

This is a small UI consistency fix in Sparrow Wallet's terminal (command-line) receive dialog. It changes how the wallet checks whether all key storage locations (keystores) use the same derivation path. Previously the comparison used raw …

Normalization of derivation-path comparisonUI-only terminal receive dialog changeNo cryptographic or signing logic modified
2ed6e385by Craig Raw+2−11 file
No security note in commit
Low 46 AI analysisMessage 60 · Adequate
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

add verification on additional satscard, tapsigner and satschip operations

This commit adds extra verification steps when Sparrow Wallet talks to certain physical Bitcoin cards (Satscard, Tapsigner, Satschip). It makes the wallet check the card's authenticity before performing sensitive operations like reading an…

Adds authentication/verification call before sensitive card operationsTargets hardware/NFC card workflows (Satscard, Tapsigner, Satschip)Defensive hardening with no functional behavior change visible in diff
7c7086f0by Craig Raw+8−02 files
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

check a paynym retrieved by payment code matches the requested code

This commit adds a safety check in Sparrow Wallet's PayNym feature. PayNyms are human-readable names linked to Bitcoin payment codes. Previously, when a user looked up a PayNym by its payment code, the wallet would trust whatever payment c…

Server response validation added: requested vs returned payment code notification address comparisonUI now uses locally derived payment code instead of server-returned payment codeThrows IllegalStateException on mismatch, indicating a security-relevant invariant
b7fb756cby Craig Raw+16−22 files
No security note in commit
Moderate 60 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

name the db file migrated from a json wallet after the opened file and improve handling for existing wallets

This commit fixes a bug in Sparrow Wallet where opening an older JSON-format wallet could accidentally overwrite or create files in unexpected locations. Previously, the app named the new database file using the wallet's internal name rath…

Path traversal / unsafe filename construction from user-controlled wallet name preventedSilent deletion of existing wallet file on name collision removedPartial migration rollback added to avoid corrupt leftover database
b09ab0cfby Craig Raw+197−62 files
No security note in commit
Moderate 59 AI analysisMessage 65 · Adequate
BS BlockstreamBlockstream Jade BitcoinHardware wallets

pin: disallow pin update on initialized units in debug mode

This commit removes a special debug-only exception that previously allowed the PIN server's public key to be changed on a Jade hardware wallet that already had a wallet set up. In normal operation, changing this public key on an initialize…

Removal of debug-mode bypass for a security-critical authorization checkProtection against pinserver public key substitution on initialized devicesDefense-in-depth for wallet PIN/server trust binding
a5667efdby Jon Griffiths+1−31 file
Vendor flagged security relevance
Low 33 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

This commit fixes a small but real bug in a Rust helper that reads fixed-size chunks from a data slice. The helper was supposed to safely return 'nothing' when asked to read past the end of the data, but it accidentally added two numbers t…

Integer overflow in bounds-checking helperContract violation: method documented to return None on out-of-bounds access could panic insteadDebug-build panic (denial of service) possible
c6e80843by Andrew Poelstra+2−11 file
Vendor flagged security relevance
Informational 15 AI analysisMessage 95 · Strong
BS BlockstreamBlockstream Jade BitcoinHardware wallets

tests: fix mnemonic handling following seed changes

This commit only changes test code for the Blockstream Jade hardware wallet. It fixes how tests set and reset the device mnemonic/seed so tests run correctly after earlier seed-handling changes. There is no change to the actual wallet firm…

85e87d4eby Jon Griffiths+32−377 files
No security note in commit
Low 49 AI analysisMessage 68 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

bip32: reject str path child index >= 2**31

This commit fixes a bug in how Electrum parsed Bitcoin wallet derivation paths typed by users. A path like "m/2147483648" was silently treated the same as "m/0'" (a hardened key), and "m/2147483649'" lost its hardening marker. The patch no…

Input validation gap in BIP32 path parserSilent reinterpretation of user-supplied index as hardened bitAmbiguous string-to-integer round-trip for derivation paths
624fd5b8by MrKalipo+20−32 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →