Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24264Commits captured
20888AI analyses
57High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20888 analyses
Highest risk·RSS
Low 34 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36080: p2p: Suspend ping timeout while downloading blocks from a peer

This change fixes a bug where Bitcoin Core could wrongly disconnect a peer during Initial Block Download (IBD). The problem happened because the node demanded a ping reply within 20 minutes even while the peer was busy sending blocks. With…

Denial-of-service self-inflicted: low-bandwidth IBD nodes could lose honest peersPing timeout logic moved to a more appropriate location with additional guard conditionsNew functional test covers the exact timeout/grace-period behavior
c7835db1by merge-script+235−183 files
No security note in commit
Low 27 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

revalidate the send amount when payments are set from a uri opened externally or a spend event so insufficient and dust warnings show

This commit fixes a UI bug in Sparrow Wallet's send form. When a payment amount was filled in automatically—such as when opening a Bitcoin payment link from another app or when triggered by a 'spend' event—the wallet did not re-run its amo…

Missing input validation for programmatically populated fieldUI warning suppression for dust and insufficient-balance checksExternal URI/spend event triggers automatic form population
8f47a8d1by Craig Raw+1−01 file
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

fix typos in keycard comments, the inverted p2pk hash and mnemonic type wording, and jade decoding error messages

This commit only fixes spelling mistakes in code comments and user-facing error messages. It changes no program logic, no security checks, and no cryptographic behavior. There is no security issue here.

5adb27e4by Craig Raw+5−54 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36128: test: add script_tests cases covering more interpreter mutants

This commit only adds new test cases to Bitcoin Core's test suite. It does not change any production consensus code. The tests are designed to catch accidental code changes ('mutants') in the script interpreter that could break consensus r…

Adds consensus-relevant test coverage for script interpreter behaviorPull request description discusses hypothetical mutants in interpreter.cpp, but these are not present in the diffNo changes to production consensus, networking, wallet, or RPC code
b3f9d8e1by merge-script+34−02 files
No security note in commit
Low 40 AI analysisMessage 55 · Thin
SW SparrowSparrow Wallet BitcoinHardware integrationSoftware wallets

support inline signed manifests in the download verifier by reading hashes from the verified signature content

This commit changes how Sparrow Wallet's download verifier reads the list of trusted file hashes. Previously, the verifier read hashes from a separate manifest file on disk. Now, it reads the hashes from the cryptographically signed conten…

previously trusted manifest was re-read from disk after signature verification, creating a TOCTOU window between signature check and hash lookupnew code parses manifest from the cryptographically covered bytes returned by PGP verificationmanifest size bounded to prevent unbounded memory buffering during verification
6ef88d84by Craig Raw+31−102 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36327: test: speed up secp256k1 fixed-base multiplication and Schnorr signing

This commit is a pure performance optimization for Bitcoin Core's internal test framework. It changes how the test code performs certain mathematical operations on the secp256k1 elliptic curve, making tests run faster. There is no change t…

b6a1b0ffby merge-script+26−131 file
No security note in commit
Low 29 AI analysisMessage 18 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Bump dependencies

This commit updates many third-party software libraries used by BTCPay Server to newer versions. The changes also adjust how FIDO2/WebAuthn security-key support is configured to match the newer library. Dependency bumps can fix security bu…

Dependency version bumps may include undisclosed security fixes in upstream packagesFido2 library major-ish upgrade (4.0.1→4.2.0) with API renames suggests upstream breaking changes, possibly including security hardeningYamlDotNet major version jump (16.3.0→18.1.0) could address parser security issues historically present in YAML libraries
03c8d8a2by Nicolas Dorier+30−297 files
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6973: units: Document the encoding feature

This commit is a documentation-only change. It adds a missing entry to the crate's feature list in the source-code documentation, describing the optional `encoding` feature. There is no code change, no behavior change, and no security impa…

7fa8b884by Andrew Poelstra+2−01 file
No security note in commit
Informational 15 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6972: units: Use third person in rustdoc summaries

This commit only fixes the grammar of code documentation comments, changing phrases like 'Construct' to 'Constructs' and 'Attempt' to 'Attempts' in three source files. It does not change any actual program logic, function behavior, or secu…

ce47c719by Andrew Poelstra+12−113 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →