Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24484Commits captured
20998AI analyses
55High-risk findings · 30d
Active security advisories
Critical

Core Lightning v26.06.9: urgent loss-of-funds security update

Core Lightning says v26.06.9 fixes a newly reported vulnerability that can lead to loss of funds. The release also contains security fixes in channel reestablishment, splicing, HTLC shutdown handling, onion and on-chain handling, gossip range queries, runes, configuration, and several remote-crash and hardening fixes.

Affected: Every Core Lightning node running v26.06.8 or earlier is affected, according to the vendor. Technical tests for the security fixes are temporarily withheld to slow exploit development while operators upgrade.

Action: Upgrade to Core Lightning v26.06.9 immediately. Download the release from https://github.com/ElementsProject/lightning/releases/tag/v26.06.9, verify the appropriate signed SHA256 manifest and checksums for your architecture, install it, restart lightningd, and confirm the running version.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20998 analyses
Highest risk·RSS
Informational 23 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: retain unlock notifications after long polling gaps

This change fixes a bug in a Monero wallet's long-polling notification system. Previously, if there was a long gap between polls, the wallet could use a height bound that was too recent and miss transactions that had since unlocked. The fi…

Functional bug in wallet notification logicPotential missed unlock notifications after polling gapsNo cryptographic, authentication, or input-validation changes
7a1a3af4by woodser+6−21 file
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1451 from levoncrypto/masternode-status

This commit simplifies how the Stack Wallet app displays Firo masternode status. Previously, the app distinguished between masternodes that were 'banned' and those that were 'revoked'. Now both conditions are shown as 'BANNED' with a red c…

No cryptographic, authentication, or transaction logic changedNo input validation, parsing, or serialization logic changedChange is limited to enum values and UI color mapping
2a92cababy Julian+5−62 files
No security note in commit
Informational 16 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

use ACTIVE/BANNED masternode statuses, revoked masternodes are banned

This commit simplifies how the Stack Wallet app labels Firo masternodes. Previously, the app distinguished between 'banned' and 'revoked' masternodes, showing banned ones in orange and revoked ones in red. Now both states are treated as 'b…

No security-relevant code paths modifiedUI-only status label and color changeNo input validation, parsing, or cryptographic changes
3d724b93by levoncrypto+5−62 files
No security note in commit
Low 29 AI analysisMessage 45 · Thin
BS BlockstreamBlockstream Jade BitcoinHardware wallets

assets: improve empty ticker support

This commit hardens how the Blockstream Jade hardware wallet handles assets that have no ticker symbol. Previously, if an asset's ticker was missing (NULL), the code could pass a NULL pointer to string-length functions, which can cause cra…

NULL-pointer dereference risk in asset ticker handlingDefensive null-check added before strlen()New test fixture for NULL ticker asset path
9d0d74d0by Mike Tolkachev+30−23 files
No security note in commit
Informational 20 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into codex/rsfiro-app-config

This commit is a routine merge that improves how the Stack Wallet app displays Firo masternode status. Previously, a masternode was shown as simply 'ACTIVE' or 'REVOKED' based only on whether it had been revoked. Now it can also show 'BANN…

No security-relevant code paths modifiedUI-only display change for masternode stateNo input validation, serialization, or authentication changes
fee7936dby Reuben Yap+30−132 files
No security note in commit
Informational 15 AI analysisMessage 70 · Adequate
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Firmware v9.27.1 verification (yaziza)

This commit adds two digital signature files for BitBox02 firmware version 9.27.1. These signatures are a third-party reproducible-build verification (called an 'assertion') created by an independent contributor named yaziza. The commit do…

6d2e6955by Yasser Aziza+0−02 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
TZ TrezorTrezor firmware BitcoinHardware wallets

chore: drop Omni support from Core and Legacy firmware

This commit removes support for the old Omni Layer protocol from Trezor hardware wallets. Omni was used for assets like USDT (Tether) on Bitcoin before those tokens moved to other blockchains. After this change, any transaction that previo…

47dc2058by Roman Zeyde+11−16614 files
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

ci: format touched files and reuse test key stubs

This commit is purely cosmetic and CI-related. It reformats several Dart UI files to match the project's code style and removes a redundant fallback block in the GitHub Actions test workflow that wrote empty placeholder API keys when real …

015a8011by Reuben Yap+221−2445 files
No security note in commit
Low 25 AI analysisMessage 81 · Strong
AQ ACINQEclair BitcoinLightning Network

Upgrade postgresql client from 42.7.11 to 42.7.12 (#3330)

This commit updates the PostgreSQL database driver used by Eclair from version 42.7.11 to 42.7.12. It is a routine dependency bump by an automated tool. The commit itself does not say what bugs the new driver fixes, but small point-release…

Dependency version bump of a database driverPoint-release upgrade may include upstream security fixes, but none are named in the commitNo application code changes or direct vulnerability evidence in the diff
972dfe99by dependabot[bot]+3−12 files
No security note in commit
Informational 15 AI analysisMessage 78 · Adequate
EL ElectrumElectrum BitcoinSoftware wallets

Merge pull request #10988 from f321x/update_security_review_ci_model

This commit updates Electrum's internal CI (continuous integration) script that runs an automated security review using Anthropic's Claude Code tool. It changes the AI model version used for reviews from 'claude-opus-5' to 'claude-opus-5-5…

CI hardening: detects and reports AI model downgrades during automated security reviewNo changes to application code, cryptography, network protocol, or build artifactsNo privilege escalation, injection, or data-exfiltration vectors introduced by the diff
638fbba8by Felix+75−111 file
No security note in commit
Moderate 62 AI analysisMessage 73 · Adequate
LL Lightning LabsLND BitcoinLightning Network

Merge pull request #11190 from Roasbeef/zpay32-reject-duplicate-payment-hashes

This change tightens how LND reads Lightning invoices (BOLT 11). Previously, if an invoice contained more than one payment hash field, LND would silently keep the first one and ignore the rest. Now it rejects the invoice entirely. The rele…

Behavior change from 'use first duplicate field' to 'reject duplicate fields'New error type ErrDuplicatePaymentHash returned on duplicate payment hash fieldsMalformed/unsupported-length duplicate payment hash now treated as duplicate and rejected
86306f89by Yong+147−106 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →