Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24369Commits captured
20930AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20930 analyses
Highest risk·RSS
Informational 19 AI analysisMessage 100 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6922: Use `try_fold` instead of `fold` in `Sum` impl

This is a code-quality and performance improvement, not a security fix. It changes how the library adds up lists of Bitcoin amounts so that it stops early once an overflow is detected, rather than continuing to process the rest of the list…

No security-relevant signal in commit message or diffRefactor preserves overflow-checking behavior (short-circuits instead of continuing)New API method `NumOpResult::from_result` is a pure inverse of existing `into_result`
86e4d5daby Andrew Poelstra+60−562 files
No security note in commit
Moderate 59 AI analysisMessage 78 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

btc: reject raw key hashes in policies

This commit fixes a bug in the BitBox02 hardware wallet's Bitcoin policy handling. Previously, the wallet accepted a specific type of unsupported script fragment called a 'raw public-key hash' (RawPkH) inside Taproot wallet policies. Becau…

Unsupported Miniscript fragment accepted by parserKey enumeration mismatch: RawPkH leaf not counted as a keyTaproot leaf sanity check bypassed during parsing
980d937dby benma's agent+29−41 file
Vendor flagged security relevance
Moderate 52 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6893: units: Reject malformed amount strings

This update fixes a bug in how the library reads Bitcoin amount strings like '1.5 BTC'. Previously, certain malformed inputs such as '.', '._', '1_', '1_.0', and '1._0' were incorrectly accepted and treated as valid amounts (often zero), i…

Input validation bypass in amount parserMalformed strings silently parsed as zero or ordinary amountsUnderscore separator placement not enforced
fcb14622by Andrew Poelstra+88−343 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 83 · Strong
FD FoundationPassport firmware BitcoinHardware wallets

Merge pull request #676 from Foundation-Devices/fix/change-verification-error-copy

This commit only changes the user-facing error message shown when the Passport hardware wallet cannot verify that a transaction's change address belongs to the wallet. The underlying security check and error handling remain exactly the sam…

1d69eb29by mjg-foundation+5−23 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
LL Lightning LabsLND BitcoinLightning Network

build: skip CI for docs-only changes and run a fast subset on drafts

This commit only changes how the project's automated GitHub test pipeline is organized. It adds a 'gate' job that decides whether a pull request only touches documentation, and if so, skips the heavy code tests. It also makes draft pull re…

098f8445by ziggie+165−141 file
No security note in commit
Low 32 AI analysisMessage 35 · Opaque
BS BlockstreamBlockstream Jade BitcoinHardware wallets

malloc_ext: fix JADE_CALLOC_DRAM

This commit fixes a macro definition for a memory-allocation helper. The macro was accidentally written to take only one argument ('size') even though the underlying function it calls needs two arguments ('number of items' and 'size of eac…

Memory-allocation wrapper macro arity mismatch fixedPotential for undefined behavior if mismatched macro were usedNo explicit security claim or CVE referenced in commit
828835ccby Daniel Newton+1−11 file
No security note in commit
Low 48 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6921: units: fix div_by_fee_rate_ceil precision

This commit fixes a rounding bug in how the rust-bitcoin library calculates the minimum transaction weight needed to pay a given fee at a given fee rate. The old code rounded the fee rate up too early, which could produce a weight slightly…

Incorrect fee-weight calculation due to premature integer roundingPotential transaction fee shortfall when using div_by_fee_rate_ceilOverflow protection added for Amount::MAX * 4_000_000 intermediate value
b31212e0by Andrew Poelstra+38−82 files
No security note in commit
Low 44 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36284: wallet: don't double discard output groups with avoidpartialspends

This is a wallet bug, not a theft or remote-code bug. When a Bitcoin Core user turns on the optional 'avoidpartialspends' or 'avoid_reuse' setting, an output group rejected during coin selection could be counted twice as 'discarded.' That …

Logic error causing double-counting of discarded UTXO groupsCan trigger false 'insufficient funds' failure in coin selectionAffects avoidpartialspends / avoid_reuse wallets only
e8e7e91aby Ava Chow+43−14 files
No security note in commit
Informational 16 AI analysisMessage 72 · Adequate
TZ TrezorTrezor firmware BitcoinHardware wallets

fix(core): consistent sign message flow

This commit changes how Trezor hardware wallets display the sign/verify message flow on two newer user-interface designs (Eckhart and Delizia). It mostly reorganizes on-screen menus so that extra details (account, derivation path, message …

UI flow consistency change onlyNo changes to cryptographic signing, verification, or authorization logicNo changes to message parsing, address derivation, or trust assumptions
7a48cf90by obrusvit+1768−17775 files
No security note in commit
Low 43 AI analysisMessage 68 · Adequate
BS BlockstreamBlockstream Jade BitcoinHardware wallets

sign_psbt: fix reply count for exact chunk sizes

This commit fixes a bug in how Blockstream Jade counts the number of message chunks needed to send back a signed Bitcoin transaction (PSBT). When the transaction size was an exact multiple of the chunk size, the device told the host there …

Integer division off-by-one in chunk/message countDevice abort on assertion when host requests non-existent chunkDenial-of-service-like symptom: valid signing flow can crash the device
4f1a1565by kkdao+38−22 files
No security note in commit
Low 37 AI analysisMessage 73 · Adequate
BS BlockstreamBlockstream Jade BitcoinHardware wallets

ui: allow tapping directly on touchscreen elements

This commit adds a new touchscreen mode for some Jade hardware wallets where users can tap on-screen buttons directly instead of only using the three virtual buttons below the screen. To reduce the risk of accidental or malicious confirmat…

New direct-touch input path added to GUI event handlingCritical-action buttons require long-press to mitigate stray or coerced tap confirmationsDestructive operations (reset, delete wallet, delete OTP) converted to critical yes/no prompts
a46aa30aby Bota+206−1111 files
Vendor flagged security relevance
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →