A patch is not the same as disclosure. CommitWatch reads security-critical commits so the rest of us don't have to — and keeps a public record of what was fixed, how clearly it was explained, and whether anyone told the users.
Read MoreOn July 31, 2026, Coinkite released Coldcard firmware v5.6.0 as an urgent hotfix for a "limited entropy bug" that produced roughly $90M in user losses. This post presents a technical analysis of what that hotfix actually addresses, what it does not, and additional security findings that users need to know about when deciding how to proceed.
Read MoreColdcard's five-year RNG failure let attackers sweep $38M from wallets this week — but seeds protected by a strong BIP39 passphrase survived. Here's why, and how TimeCapsule makes that layer practical.
Read MoreAn important security vulnerability has been discovered in pfSense that affects installations with captive portal enabled with certain configurations. This vulnerability requires NO AUTHENTICATION to exploit.
Read MoreThe Karma-X Security Research Team discovered a critical cryptographic vulnerability in the Coldcard hardware wallet's Delta PIN feature that allowed full private key recovery with just two transaction signatures.
Read MoreKarma-X has discovered a critical vulnerability in the ColdCard wallet which could compromise user funds. Traveling with a ColdCard device could present significant risk to user funds and it is advised to use caution until patches are released.
Read MoreKarma-X Research Team has discovered multiple critical vulnerabilities in NVIDIA TensorRT
Read MoreKarma-X Research Team has discovered multiple critical security vulnerabilities in Ollama, the popular open-source AI framework.
Read MoreA template injection vulnerability exists in LangChain's Mustache template processing engine that allows attackers to execute arbitrary Python code through user-controlled callable scopes
Read More