Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24482Commits captured
20997AI analyses
55High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20997 analyses
Highest risk·RSS
Low 46 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11321

This patch changes the order in which two internal locks are acquired in a Monero blockchain-checking function. In multi-threaded software, taking locks in the wrong order can cause a 'deadlock,' where two parts of the program wait forever…

Lock-order change in concurrent codePotential deadlock (AB-BA) between m_tx_pool and m_blockchain_lockDenial-of-service risk if a node can be frozen
d1bcbc76by tobtoht+2−11 file
No security note in commit
Low 37 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11274

This commit fixes a bug in Monero's wallet software where the program would partially change account labels before checking whether all requested accounts actually exist. The fix moves the boundary check to the very beginning so the operat…

Atomicity bug: partial state mutation before full input validationOut-of-bounds access prevented by early validation loopFunctional test added for negative-path rejection
d5ad72e5by tobtoht+24−02 files
No security note in commit
Moderate 59 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11265

This Monero wallet update adds safety checks when a wallet imports 'multisig_info' data shared between co-signers in a multi-signature wallet. It now rejects files where the declared signer doesn't match the file header, or where the numbe…

Input validation added to deserialization pathMismatch between header signer and body signer now rejectedUnexpected counts of partial key images and signing nonces now rejected
3b18aeb1by tobtoht+120−02 files
No security note in commit
Moderate 61 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11244

This update adds a safety check in the Monero wallet software. When the wallet asks a network node (daemon) for details about specific transactions, it now verifies that the transactions it gets back are actually the ones it asked for. Wit…

Missing input validation on daemon RPC responseTrust boundary crossing between wallet client and daemonPotential transaction substitution / response mismatch
c0944a04by tobtoht+4−01 file
No security note in commit
Moderate 62 AI analysisMessage 58 · Thin
LL Lightning LabsLND BitcoinLightning Network

Merge pull request #11212 from ziggie1984/disable-legacy-channels

This change stops LND from opening new Lightning channels using the old 'legacy' commitment format. The legacy format makes it harder to recover funds if something goes wrong, because the money owed to you is tied to a secret key that chan…

Prevents opening new channels with the legacy commitment type, whose tweaked to_remote output complicates data-loss recoveryCloses a negotiation path where an empty channel_type TLV bypassed feature checks and forced a legacy channelAdds explicit RPC and wire rejection with a dedicated error code
112cb5f3by ziggieXXX+265−4716 files
Vendor flagged security relevance
Informational 19 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35675: mining: add block template manager

This is a large internal code reorganization (refactor) in Bitcoin Core. It creates a new BlockTemplateManager class that takes over block-template creation, block submission, and tip-waiting helpers that were previously spread across seve…

Large refactor touching mining, RPC, interfaces, and test shutdown pathsNew object lifetime dependency: BlockTemplateManager holds references to mempool, chainman, and notifications; explicit reset ordering added in Shutdown/InitAndLoadChainstate/test setupsRemoval of early-init node.mining interface; BlockTemplateManager is now created after chainstate load, with a comment that it must exist before setChainstateLoaded(true) unblocks IPC waiters
5c726f20by Ryan Ofsky+561−44926 files
No security note in commit
Informational 13 AI analysisMessage 60 · Adequate
BS BlockstreamBlockstream Jade BitcoinHardware wallets

urldecode: use plain strlen in self-tests of libjade

This commit only changes the internal test file for a URL-decoding helper. It swaps a custom string-length macro for the standard C strlen() function inside test data. The actual product code that users rely on is not changed, and there is…

b39a7a20by Mike Tolkachev+27−291 file
No security note in commit
Moderate 50 AI analysisMessage 45 · Thin
BS BlockstreamBlockstream Jade BitcoinHardware wallets

assets: support tickers up to 24 characters

This commit updates the Blockstream Jade hardware wallet to support longer asset tickers (up to 24 characters) and adds validation to reject malformed tickers. It also fixes a potential display bug where a ticker longer than 8 characters c…

Buffer size increased from 8 to 25 bytes to match new ticker maximumNew input validation added for asset ticker length and character setsnprintf precision argument cast from size_t to int to avoid undefined behavior on some platforms
cc5859a6by Mike Tolkachev+36−53 files
No security note in commit
Informational 21 AI analysisMessage 92 · Strong
LL Lightning LabsLND BitcoinLightning Network

build: read live PR labels in check-label action

This is a GitHub Actions workflow fix, not a vulnerability in the LND lightning node software itself. It changes how a CI check reads pull-request labels so that re-running a failed job sees labels added after the run started. The change a…

New GitHub API token usage (GH_TOKEN: ${{ github.token }})New workflow permission added: pull-requests: readCI-only change; no application code modified
45c9cfffby ziggie+33−62 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

docs: update api docs

This commit only updates generated API documentation (Javadoc HTML files). It does not change any actual program code, so it cannot introduce or fix a security vulnerability on its own.

bf0ac8c3by woodser+278−2317 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: isolate key image import test

This commit only changes a test file. It rewrites one wallet test so that it uses a separate offline wallet instead of importing outputs back into the same wallet. There is no change to production code and no security fix or vulnerability …

86567073by woodser+16−151 file
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →