conv.

All stories
SecurityActive · 16h

Radicle discloses critical network protocol vulnerabilities affecting all versions

Unencrypted traffic and weak node authentication flaw discovered in peer-to-peer git hosting protocol; fix requires breaking protocol change.

What to know

  • Radicle's network protocol has lacked encryption and proper authentication since inception, exposing private repository contents to attackers on the network path between syncing nodes.
  • The vulnerability requires a breaking protocol change—replacing the custom Noise implementation with iroh—which will partition the network and require a major version bump with no backward compatibility.
  • Radicle disclosed the flaw 91 days after being reported (June 24 to Sept 23), before releasing a fix, but the confidentiality breach has already affected every deployed version.

The dispute Whether Radicle's transparent pre-fix disclosure offsets the severity of the vulnerability and the engineering failures that allowed it to persist undetected for three years. · positions read across 37 posts and comments

most voices

The vulnerability reveals serious engineering failures; basic protocol testing (packet inspection) was never performed.

  • “No offense, but how can you build a protocol that accidentally does not encrypt stuff at all? Don't you at some point look at the wires?”

    freddyb · Lobsters ↗
many voices

Radicle deserves credit for transparent pre-fix disclosure, which is uncommon industry practice.

  • “Well, they at least get some kudos for *admitting* it.”

    retr0id · Lobsters ↗
some voices

The breaking protocol change and network partition may be fatal to Radicle's adoption; recovery will be very difficult.

  • “This seems like death; I'm not sure how they can recover from this.”

    veqq · Lobsters ↗

Radicle Decentralized git hosting platformKonstantinos Maninakis Security researcher

How it unfolded 4 developments, newest first · click a bar or a number to jump articlespostscomments

Peak 8 pieces in one half hour at Yesterday, 1 PM; 40 pieces over 17 hours (1 article · 3 posts · 36 comments) Yesterday, 9:58 AM — quietYesterday, 10:28 AM — 1 piece · 1 post — Lobsters 1Yesterday, 10:58 AM — 2 pieces · 1 article · 1 post — Hacker News 1, Newswires 1Yesterday, 11:28 AM — quietYesterday, 11:58 AM — 2 pieces · 2 comments — Hacker News 2Yesterday, 12:28 PM — 2 pieces · 2 comments — Lobsters 2Yesterday, 12:58 PM — 1 piece · 1 comment — Lobsters 1Yesterday, 1:28 PM — 8 pieces · 8 comments — Lobsters 5, Hacker News 3Yesterday, 1:58 PM — 6 pieces · 6 comments — Lobsters 4, Hacker News 2Yesterday, 2:28 PM — 3 pieces · 3 comments — Lobsters 3Yesterday, 2:58 PM — 2 pieces · 2 comments — Hacker News 1, Lobsters 1Yesterday, 3:28 PM — 2 pieces · 2 comments — Hacker News 1, Lobsters 1Yesterday, 3:58 PM — 2 pieces · 2 comments — Lobsters 2Yesterday, 4:28 PM — 1 piece · 1 comment — Lobsters 1Yesterday, 4:58 PM — 2 pieces · 2 comments — Lobsters 2Yesterday, 5:28 PM — quietYesterday, 5:58 PM — 1 piece · 1 comment — Lobsters 1Yesterday, 6:28 PM — quietYesterday, 6:58 PM — 1 piece · 1 post — Mastodon 1Yesterday, 7:28 PM — quietYesterday, 7:58 PM — quietYesterday, 8:28 PM — quietYesterday, 8:58 PM — quietYesterday, 9:28 PM — 1 piece · 1 comment — Lobsters 1Yesterday, 9:58 PM — quietYesterday, 10:28 PM — quietYesterday, 10:58 PM — quietYesterday, 11:28 PM — quietYesterday, 11:58 PM — quietToday, 12:28 AM — quietToday, 12:58 AM — quietToday, 1:28 AM — 1 piece · 1 comment — Lobsters 1Today, 1:58 AM — 1 piece · 1 comment — Lobsters 1Today, 2:28 AM — 1 piece · 1 comment — Lobsters 1 1–234
12 PM4 PM8 PMnow · 2:58 AM ET
  1. 4

    Mixed assessmentCautious credit for transparency, skepticism about recovery

    While some commenters acknowledged Radicle's decision to disclose before releasing a fix as commendable, others questioned the project's viability. One commenter called the situation 'death' for private repository use. A separate technical analysis showed session keys were established but never used for encryption.

    “Well, they at least get some kudos for *admitting* it.”
    — retr0id
    • Well, they at least get some kudos for *admitting* it.

      retr0iddistributed,security,vcs13h ago24▲view on Lobsters ↗
    2 more of the top 3 · 32 posts in this stretch
    • Radicle has been one of those projects that had seemed interesting, but something always bothered me about it. (I think it was very highly tied to the cryptocurrency movement for a while? And the Cyphernet GitHub org seems to have rebranded from a DAO?)This, unfortunately, kinda seals the deal on never using this thing, at least not for anything I…

      jscdHacker News11h agoview on Hacker News ↗
    • nmott@infosec.exchange

      this is, indeed, radical https:// radicle.dev/2026/09/23/disclos ure-of-vulnerability-in-network-protocol.html

      nmott@infosec.exchangeMastodon7h agoview on Mastodon ↗
    all of them →
  2. 3

    Technical community questions protocol design and testing practices

    Developers and security professionals expressed alarm at the fundamental nature of the flaw—an entire protocol lacking encryption despite using Noise. Comments focused on the absence of basic verification like packet inspection (Wireshark) and questioned how this escaped testing for 3+ years.

    “No offense, but how can you build a protocol that accidentally does not encrypt stuff at all? Don't you at some point look at the wires?”
    — freddyb
    • No offense, but how can you build a protocol that accidentally does not encrypt stuff at all? Don't you at some point look at the wires? Re-implement the protocol as a different clients - for tests?

      freddybdistributed,security,vcs14h ago83▲view on Lobsters ↗
    2 more of the top 3 · 5 posts in this stretch
    • >This was reported to us by Konstantinos Maninakis on 2026-06-24.announcement 3 months later is not super great, considering that the current advice is "Stop using private repositories (over the network) until the security update is released."

      john_strinlaiHacker News14h agoview on Hacker News ↗
    • Yeah, I think your tone is entirely valid. I've poked at Radicle in the past, and I love what it in theory is doing, but it...I dunno how to put this, but after being in the industry for so long, you kind of get a feel for something being *off* in a project? I'd have a hell of a time articulating what I was noticing, but it was enough I stopped…

      geckodistributed,security,vcs13h ago24▲view on Lobsters ↗
    all of them →
  3. 1

    Radicle announces major version bump and protocol migration plan

    Due to lack of version negotiation and backward-incompatible fixes needed, Radicle announced a major version bump. The fix involves replacing the custom Noise protocol with iroh, an open-source peer-to-peer stack, requiring a breaking network change that will partition upgraded and non-upgraded clusters.

    “The resolution involves replacing Radicle's networking protocol (currently a custom protocol using Noise) with iroh, an open source peer-to-peer networking stack built on open standards.”
    — Radicle
  4. 2

    Radicle discloses network protocol vulnerabilities publicly

    Radicle publicly disclosed two critical vulnerabilities: unencrypted network traffic between nodes and weak node authentication. The vulnerabilities expose private repository contents to attackers on the network path. Radicle published the disclosure before releasing a fix, stating that no fix can undo exposures that have already occurred.

    “We are publishing this before the security update is available. You can act on it today, and no fix we release later can undo an exposure that has already happened.”
    — Radicle
    1. first by HN Frontpage, 15h ago

  5. background

    Konstantinos Maninakis reports vulnerabilities to Radicle — Security researcher Konstantinos Maninakis discovered and reported two critical flaws in Radicle's network protocol to the team.

What people are saying 18 voices from 2 sites · best of 37 · verbatim

Still unanswered
  • Why did Radicle take 91 days (June 24 to September 23) to disclose after learning of the vulnerability?
  • How can users ensure their private repositories were not compromised during the window of exposure?
  • Will the network partition from the breaking protocol change cause a permanent split in the Radicle ecosystem?