Bitcoin Core 32.0
The 32.x branch split from master on 11 September. v32.0rc2 was tagged on 18 September, and the final release is aimed at 10 October.
UNREADABLE COINS
#34931, merged 8 Sep. An unreadable UTXO database entry used to be treated as a missing coin, so a valid block that spent it would be rejected for good. The node now stops with a database error. The PR says this cannot be triggered in practice today; the fix is defensive.
WALLETNOTIFY
#36048, merged 2 Sep. On non-Windows builds, an authenticated RPC caller allowed to create wallets could inject shell commands through a wallet name substituted into
-walletnotify. Present since v24. Not reachable over P2P.BIP54 TEMPLATES
#35949, merged 7 Sep. Block templates now follow BIP54's Murch–Zawy timestamp rule for the last block of each difficulty period. Templates only, with no consensus change, ahead of a possible consensus-cleanup soft fork.
BACKPORTS
Open backport pull request #36300 proposes two later master merges for 32.x: the fee-estimator fallback (#36365) and private broadcast marked experimental (#36309).
On Master, for 33
Merged after the branch split, so these are not in 32.0 unless backported. None changes consensus rules.
MAXFEERATE
#29278, merged 25 Sep. Adds a wallet
-maxfeerate startup option, so the fee-rate ceiling is no longer the same setting as maxtxfee.SIGHASH_SINGLE
#35984, merged 25 Sep. Skips signing a
SIGHASH_SINGLE input that has no corresponding output, so walletprocesspsbt no longer fails on that case.FEE ESTIMATES
#36365, merged 29 Sep. While
mempool_policy cannot estimate yet, fee RPCs fall back to block_policy. The default estimator option is renamed from none to auto.ALSO MERGED
A
listrawtransactions RPC (#35813), atomic wallet encryption-state updates (#35752), a block template manager for mining (#35675), and private broadcast marked experimental (#36309).Lightning Security Releases
Disclosures, security releases, and release candidates from August and September.
ECLAIR
Matt Morehouse, Delving 24 Sep, for v0.13.1 and earlier. One maximum-length
init message caused about 300 MB of heap churn. A 64 KB channel query inflated to 64 MB through zlib, an encoding BOLT 7 deprecated four years ago. Fixed in v0.14.0 (May 2026). v0.14.3 (14 Sep) is a later security release.CLN PING
Erick Cestari, Optech #421. Before 25.09 (September 2025), a peer that finished the handshake could request maximum-size
pong replies and never read them, until the node ran out of memory. No channel needed. Fixed with backpressure in connectd. 26.06.7 (28 Aug) and 26.06.8 (22 Sep) are later security releases.LDK
v0.2.6 (Optech #422) fixes a channel manager that could fail to deserialize after a rejected payment, and a splice counterparty inflating this node's fee contribution.
v0.3-rc2 (21 Sep) is the splicing candidate: RBF of pending splices, splice-in and splice-out together, and async signing.LND
v0.21.4-beta.rc1 and v0.20.5-beta.rc1, 25 Sep. Fixes include HTLC interceptor replays, an AMP failure cancelling a whole invoice, and rejecting BOLT 11 invoices with more than one payment hash. Separately, ZmnSCPxj's forwardable-peerswap post argues for rebalancing through forwarders instead of splicing.BTCPay, LND, and HWI
Two Lightning operator incidents from August, and the hardware-wallet bridge Bitcoin Core uses.
BTCPAY
Optech #418, 14 August. BTCPay Server before 2.4.2 let an unauthenticated remote attacker read an LND node's macaroon files and spend through that node. The project says this was exploited and funds were stolen. Operators using LND were told to upgrade to 2.4.2 and LND 0.21.1, audit the node, and rotate the macaroons. On-chain wallets, and deployments on other Lightning implementations, were not exposed.
LND CLOSES
Bastien Teinturier, Optech #419, 21 August. Before LND 0.20.0, a cooperative close was treated as final after one confirmation. A reorg could then confirm an old revoked commitment, and the node would not publish a penalty. Fixed in February 2026. He knows of nobody who lost funds. The patch waits at least six confirmations, as BOLT 5 already asked.
HWI
Ava Chow, Optech #420, 28 August. HWI, the Python program Bitcoin Core uses to reach hardware signers, is moving to maintenance and is expected to be archived. She says almost all of the work has been one person, and that Python cannot be reproducibly bundled into Core. MuSig2 support will be finished first, in what she expects to be the last release. She names Wizardsardine's BHWI, in Rust, as a possible replacement.
BIP352 Cryptography, No Wallet Yet
Pull request #35301 merged 23 Sep 2026, on master for 33. Bitcoin Core still cannot send or receive silent payments.
WHAT MERGED
#35301 adds a libsecp silent-payments module and the BIP's test vectors. It works on public and private keys, with no wallet or transactions involved. Labels are deferred. This is the second attempt, after #28122, built on libsecp #1765. Wallet integration is tracked in issue #28536.
WHAT A USER CAN DO
Nothing new in Bitcoin Core's wallet yet; sending and receiving are later pull requests. Sparrow already sends to silent payment addresses, and has received them since 2.5.0 in May.
OUTSIDE CORE
average_gary sketches coinbase payouts to silent payment addresses over Stratum v2 (Optech #421). Rob Segers measured BlindBit through block 965,089: about 2.1 times the bytes of taproot-only filters plus tweak data, but no false positives and no per-match block fetches (Optech #422).
BIP and PSBT Edits
Spec work from September. One open pull request says the Silent Payments v0 test file does not check the signatures it contains.
BIP375 VECTORS
BIPs #2316 is open. It says every P2WPKH program in the vectors is
SHA256(pubkey)[:20] instead of HASH160(pubkey), and none of the 42 ECDSA PSBT_IN_PARTIAL_SIG values verifies. The reference validator does not check signatures, so no test failed.BIP376
BIPs #2276 merged 22 Sep: keep
PSBT_IN_WITNESS_UTXO after finalization, so Taproot signing still has the witness UTXO.MERGED
BIP138 (21 Sep): encryption for wallet backups other than the seed, followed by a run of clarifications. BIP461 (16 Sep): deterministic ECDSA, with low-R grinding so signatures are at most 70 bytes. Descriptor BIPs 379–390, except 388, moved to the Specification type. BIP174 gained a combiner test vector and a missing registry row.
BIP-54 AND OPEN FIXES
BIP-54 is the consensus-cleanup soft-fork proposal. This month: a Delving check of chain-length bounds, a test-vector tree format (merged), and wording nits from Calvin Kim's spec-only btcd implementation (open). Also open: a BIP-346 reference-implementation fix for two-byte index parsing.