Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24370Commits captured
20930AI analyses
53High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20930 analyses
Highest risk·RSS
Informational 19 AI analysisMessage 93 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: drop Omni support from Core and Legacy firmware

This commit removes support for the old Omni Layer protocol from Trezor hardware wallets. Omni was used for assets like USDT (Tether) on Bitcoin before those tokens moved to other blockchains. After this change, any transaction that previo…

47dc2058by Roman Zeyde+11−16614 files
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

ci: format touched files and reuse test key stubs

This commit is purely cosmetic and CI-related. It reformats several Dart UI files to match the project's code style and removes a redundant fallback block in the GitHub Actions test workflow that wrote empty placeholder API keys when real …

015a8011by Reuben Yap+221−2445 files
No security note in commit
Low 25 AI analysisMessage 81 · Strong
AQ ACINQEclair BitcoinLightning Network

Upgrade postgresql client from 42.7.11 to 42.7.12 (#3330)

This commit updates the PostgreSQL database driver used by Eclair from version 42.7.11 to 42.7.12. It is a routine dependency bump by an automated tool. The commit itself does not say what bugs the new driver fixes, but small point-release…

Dependency version bump of a database driverPoint-release upgrade may include upstream security fixes, but none are named in the commitNo application code changes or direct vulnerability evidence in the diff
972dfe99by dependabot[bot]+3−12 files
No security note in commit
Informational 15 AI analysisMessage 78 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

Merge pull request #10988 from f321x/update_security_review_ci_model

This commit updates Electrum's internal CI (continuous integration) script that runs an automated security review using Anthropic's Claude Code tool. It changes the AI model version used for reviews from 'claude-opus-5' to 'claude-opus-5-5…

CI hardening: detects and reports AI model downgrades during automated security reviewNo changes to application code, cryptography, network protocol, or build artifactsNo privilege escalation, injection, or data-exfiltration vectors introduced by the diff
638fbba8by Felix+75−111 file
No security note in commit
Moderate 62 AI analysisMessage 73 · Adequate
LL Lightning LabsLND BitcoinLightning Network

Merge pull request #11190 from Roasbeef/zpay32-reject-duplicate-payment-hashes

This change tightens how LND reads Lightning invoices (BOLT 11). Previously, if an invoice contained more than one payment hash field, LND would silently keep the first one and ignore the rest. Now it rejects the invoice entirely. The rele…

Behavior change from 'use first duplicate field' to 'reject duplicate fields'New error type ErrDuplicatePaymentHash returned on duplicate payment hash fieldsMalformed/unsupported-length duplicate payment hash now treated as duplicate and rejected
86306f89by Yong+147−106 files
No security note in commit
Informational 12 AI analysisMessage 90 · Strong
EL ElectrumElectrum BitcoinSoftware wallets

ci: security review: warn if the model got downgraded

This commit updates Electrum's own CI security-review script. It adds detection and warnings when the automated code reviewer (Claude Code) silently falls back to a different AI model, for example after a content-policy refusal. It does no…

CI-only changeNo modification of wallet, crypto, networking, or build artifactsAdds detection for AI model fallback/downgrade in automated security review
ace2ca7aby f321x+74−101 file
No security note in commit
Low 35 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4709

This change adjusts how the Monero GUI wallet stores and passes login credentials for remote daemon connections. Previously, daemon username/password and 'trusted daemon' status were kept as persistent properties on the wallet object and r…

Credential scoping/lifetime reductionRemoval of persistent daemon login state from wallet objectDefense against cross-connection credential reuse
a5c305deby tobtoht+7−63 files
No security note in commit
Informational 19 AI analysisMessage 59 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4693

This commit fixes a display bug in the Monero GUI wallet's transaction history. Previously, when sorting transactions by block height, failed transactions were incorrectly treated like pending ones and shown at the top of the list. The fix…

UI display logic correction for transaction state classificationTightened conditional for treating transactions as pendingNo memory safety, cryptographic, or authorization changes observed
baef8be9by tobtoht+14−52 files
No security note in commit
Informational 15 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4692

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments with multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it …

0f8a1cf4by tobtoht+84−185 files
No security note in commit
Moderate 58 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4690

This update fixes a timing bug in the Monero wallet's send screen. If a user quickly changed or cancelled a payment while a transaction was still being prepared in the background, the wallet could accidentally show or use the wrong transac…

Race condition between asynchronous transaction creation and UI state changesUse-after-free / dangling pointer risk from stale PendingTransaction objectsPotential wrong-transaction confirmation or commit due to stale async result
c72adf62by tobtoht+57−243 files
No security note in commit
Informational 21 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4665

This commit adds a feature that lets users scan a QR code to restore a Monero wallet from its secret keys. The change itself is a feature addition, not a fix for a known vulnerability. There is one minor security-relevant detail: the QR co…

New QR URI parser handles secret keys (secret_view_key, secret_spend_key) and restore heightAddress validation is performed before accepting parsed restore URIScheme changed from monero_wallet: to monero-wallet:
68327c0aby tobtoht+52−13 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →