Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24369Commits captured
20930AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20930 analyses
Highest risk·RSS
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 15 AI analysisMessage 25 · Opaque
CK CoinkiteCOLDCARD firmware BitcoinHardware wallets

Show Seed Vault names for temporary seeds

This commit adds a user-facing preference that lets a COLDCARD owner optionally replace the temporary seed's fingerprint (XFP) on the home screen with the friendly name stored in the Seed Vault. It is a cosmetic UI enhancement with no secu…

5a18e566by scgbckbone+56−55 files
No security note in commit
Informational 15 AI analysisMessage 77 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core): add new line on Eckhart address mismatch screen

This commit is a cosmetic UI fix for the Trezor hardware wallet's Eckhart layout. It adds a line break so that a support URL appears on its own line when the device shows an address mismatch warning. There is no security-relevant change to…

99cb0ffdby Michal Kazda+1−01 file
No security note in commit
Informational 18 AI analysisMessage 85 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core): use buttons__cancel in Delizia menu to cancel PIN setup

This is a tiny user-interface wording fix in the Trezor hardware wallet firmware. It changes the label on one menu button from a long translated phrase ('cancel setup') to a shorter generic word ('Cancel') so that translations fit on scree…

UI wording change onlyNo logic or cryptographic changeNo changelog entry (suggests minor fix)
7a1b8121by Michal Kazda+1−11 file
No security note in commit
Informational 15 AI analysisMessage 82 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

test(core): add embit 0.8.0 (for PSBT parsing)

This commit only adds a new Python test dependency called 'embit' version 0.8.0 to the project's dependency files. It is explicitly marked as being for testing PSBT (Partially Signed Bitcoin Transaction) parsing and end-to-end test vectors…

b5d19ccdby Roman Zeyde+9−02 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 85 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

build(crypto): update `crypto/Makefile` to use `-std=gnu11`

This commit simply changes the C language standard version used to compile the crypto library from GNU C99 to GNU C11. It is a routine build-system update with no security-relevant code change and no functional impact on its own.

fafc7d72by Roman Zeyde+1−11 file
No security note in commit
High 76 AI analysisMessage 53 · Thin
LD LedgerLedger Bitcoin app BitcoinHardware wallets

Merge pull request #568 from LedgerHQ/locktimes

This commit fixes how the Ledger Bitcoin app decides the 'lock time' for a transaction when signing a PSBTv2. Previously, the app always used the global fallback lock time and ignored per-input required lock times. That meant a wallet or a…

Fixes incorrect handling of PSBTv2 per-input locktime fieldsChanges what the signature commits to (nLockTime) for PSBTs using required locktimesAdds validation and rejection for conflicting or out-of-range locktime values
58ab28b3by Salvatore Ingala+1085−916 files
Vendor flagged security relevance
Moderate 67 AI analysisMessage 73 · Adequate
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Merge pull request #7599 from NicolasDorier/fix/invoice-list-store-permissions

This change fixes a permission problem in BTCPay Server's invoice list. Previously, the invoice list page accepted a 'storeid:' search filter or a StoreId parameter that could let a user see invoices from stores they were not supposed to a…

Authorization boundary enforced by scoping query to route-supplied store IDRemoval of user-controlled StoreId from view modelSearch filter 'storeid:' no longer expands the set of stores queried
5ef1b9f8by Nicolas Dorier+31−304 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Low 46 AI analysisMessage 93 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

chore(crypto): ensure `secp256k1_context` alignment

This commit fixes how a memory buffer used by the secp256k1 cryptographic library is aligned in memory. The library requires the buffer to be aligned for any data type, but the previous code used a plain byte array, which could be misalign…

Memory alignment hardening for cryptographic context bufferUndefined behavior mitigation in secp256k1-zkp preallocated context creationPotential platform-dependent misalignment risk removed
93860f05by Roman Zeyde+7−11 file
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →