All Radicle versions leak private repository contents over the network—network traffic is unencrypted and peer authentication is broken—requiring immediate repo blocking and a major version bump to fix.
Summary
If you're syncing private repos via Radicle, assume they're compromised; anyone observing the network path between nodes reads the data. You must stop seeding private repos now and rotate any credentials stored in them.
Why it matters
If you're syncing private repos via Radicle, assume they're compromised; anyone observing the network path between nodes reads the data. You must stop seeding private repos now and rotate any credentials stored in them.
Implementation verdict
Stop using private repositories over Radicle network immediately. Use `rad ls --private --all` to list affected repos, then `rad block <RID>` on each. Treat all private repos synced to other nodes as leaked. Fix requires replacing the transport layer with iroh (backwards-incompatible major release). Not production-safe for private code until patched.
Sources
Dev Signal
Get briefs like this in your inbox — free, every weekday.
100+ sources compressed into one 4-minute read. Ranked, cited, implementation-ready.