Continuous public-repository analysis

Open source.
Not open secrets.

We watch what security-critical projects change—then translate the code into clear, independent intelligence anyone can understand.

34Projects watched
24175Commits captured
20836AI analyses
56High-risk findings · 30d
Active security advisories
High

Core Lightning: disable experimental features immediately

Core Lightning is investigating a potential issue affecting experimental features that may impact user funds. The vendor urges every Core Lightning operator running experimental features to disable them immediately.

Affected: Core Lightning nodes with one or more experimental features enabled. The vendor has not yet identified the affected feature, versions, trigger, or whether exploitation or fund loss has occurred.

Action: Follow the vendor instruction and disable all experimental features immediately. Check lightningd configuration and startup arguments for experimental options, restart with them disabled, and do not re-enable them until Core Lightning publishes further guidance.

Read source ↗
Critical

Liquid Network: ~4,000 BTC withdrawn in critical peg incident

Liquid confirms that purported white-hat actors withdrew roughly 4,000 BTC (about $320 million) from its federation wallet through the SideSwap PAK. Liquid says the PAK and other federation keys were not compromised. The actors have not yet returned the funds. Independent public analysis points to a newly introduced range-proof cache-key flaw, but Liquid has not yet published its root-cause report.

Affected: The L-BTC peg and Liquid federation reserves are affected. Bridge nodes are disabled, the sidechain is paused, and exchanges have suspended L-BTC deposits and withdrawals. Liquid says other issued assets, including USDT, DePix, and RWAs, are unaffected; Bitcoin's base layer is not affected.

Action: Do not initiate Liquid peg-ins, peg-outs, swaps, or L-BTC exchange deposits or withdrawals while the network is paused. Follow official Liquid and Blockstream updates, and treat L-BTC peg exposure as impaired until reserves are restored and a verified fix and incident report are published.

Read source ↗
Critical

BTCPay Server: actively exploited LND credential theft

BTCPay confirms that an unauthenticated remote attacker could obtain LND .macaroon credentials, take control of affected LND nodes, and move funds. The vendor reports confirmed exploitation and stolen funds.

Affected: BTCPay Server versions before 2.4.2, including 2.4.2 release candidates, when used with LND. BTCPay says other Lightning implementations are not exposed to this specific credential risk.

Action: Update to BTCPay Server 2.4.2 and LND 0.21.1 immediately, review node activity, and rotate credentials. If you cannot update now, take the affected server offline.

Read source ↗
The watch feed

Changes worth understanding

AI analysis is published as generated. Community notes appear after human validation.

20836 analyses
Highest risk·RSS
Informational 24 AI analysisMessage 50 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: send amounts to wallet rpc as json numbers for v0.18.5.3

This commit changes how the Java wallet library sends monetary amounts to the Monero wallet RPC server. Previously, amounts were converted to strings before being sent; now they are sent as JSON numbers. This is a compatibility fix for Mon…

Data type mismatch between client and RPC server could lead to failed or misinterpreted transactionsAmount handling changes in transaction creation and reserve proof generation pathsNo input validation or bounds checks added in the patch
6d0cd696by woodser+3−31 file
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
High 79 AI analysisMessage 91 · Strong
RB Rust Bitcoinrust-bitcoin BitcoinCryptographic libraries

Merge rust-bitcoin/rust-bitcoin#6920: primitives: Bound aggregate size and weight while decoding

This update fixes a memory-exhaustion risk in the rust-bitcoin library's streaming decoders for Bitcoin blocks, transactions, and witness data. Previously, an attacker could send many individually legal pieces of data that, when added toge…

CWE-770: Allocation of Resources Without Limits or ThrottlingCWE-400: Uncontrolled Resource ConsumptionDenial-of-Service via malicious deserialization input
4a40980aby Andrew Poelstra+336−184 files
Vendor flagged security relevance
Moderate 63 AI analysisMessage 35 · Opaque
BT BTCPay ServerBTCPay Server BitcoinLightning NetworkPayment infrastructure

Improve internal network detection

This commit rewrites how BTCPay Server decides whether a network address is 'internal' versus 'public'. The old check only recognized a few private ranges (local loopback and RFC1918). The new check recognizes many more special-use ranges,…

Widens classification of addresses as internal/privateAdds coverage for CGNAT (100.64.0.0/10), link-local (169.254.0.0/16), documentation/test nets, multicast, and IPv6 special-use rangesAdds unit tests for internal-network detection, indicating correctness is important
e3e29dc0by Nicolas Dorier+76−12 files
No security note in commit
Low 32 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #178 from MAGICGrants/2.1.0-release-fixes

This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …

New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
320c02ceby Justin Ehrenhofer+383−362427 files
No security note in commit
Informational 3 AI analysisMessage 0 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update pins

This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…

Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
7125d971by Justin Ehrenhofer+25−252 files
No security note in commit
Informational 0 AI analysisMessage 45 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'main' into 2.1.0-release-fixes

This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…

50b25b5eby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 18 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Skip fetching unused submodules

This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …

Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
8c5b00d3by Justin Ehrenhofer+9−33 files
No security note in commit
Informational 0 AI analysisMessage 58 · Thin
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #179 from MAGICGrants/update-moneroc-libs

This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…

3df9967aby Justin Ehrenhofer+0−07 files
No security note in commit
Informational 0 AI analysisMessage 35 · Opaque
MG MAGIC GrantsSkylight Wallet MoneroPrivacy protocolsSoftware wallets

Update monero_c libraries

This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …

2cf30607by SamsungGalaxyPlayer+0−07 files
No security note in commit
Low 48 AI analysisMessage 50 · Thin
BB BitBoxBitBox02 firmware BitcoinHardware wallets

Merge remote-tracking branch 'agent/benma-agent/backup-buffer-zeroization'

This commit changes how the BitBox02 hardware wallet stores backup data so that the seed (the secret that protects cryptocurrency) is automatically wiped from temporary memory buffers after use. It also keeps the backup file format compati…

Sensitive seed material is now explicitly zeroized on Drop for the BackupData protobuf message.Encoded backup buffer is wrapped in Zeroizing to clear ciphertext buffer after SD write.Backup object is dropped before SD operations that could suspend or return early, reducing window where seed-bearing plaintext resides in RAM.
e5755430by Marko Bencun+147−334 files
No security note in commit
01
Why commit watching?

Security should leave a paper trail.

A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.

Why we built this →