The peer-to-peer code collaboration platform Radicle has revealed two critical security flaws in its core communication protocol that strip away confidentiality protections across every node release published to date. The defects let attackers positioned on the network path read private repository data in plaintext and fake the identity of nodes on connection allow-lists. Because the current protocol design doesn't include version negotiation capabilities, project maintainers can't roll out a backward-compatible fix, leading them to urge users to immediately stop clearnet private repository operations until a major architectural redesign is released.
The vulnerability disclosure details two separate protocol-level breakdowns inside radicle-node, the primary daemon that governs peer synchronization. Independent engineer Kostis Maninakis discovered that although Radicle performs a Noise Protocol Framework handshake when establishing connections, the daemon throws away the resulting cipher states right after negotiation completes. Radicle uses a three-message Noise XK handshake pattern over raw TCP sockets, where the initiator and responder swap ephemeral keys and long-term public keys to create two symmetric session keys in a step known as the split. However, radicle-node leaves these derived keys unread in memory, and all subsequent communication—including gossip metadata, routing tables, and raw Git object packs—is sent directly across the unencrypted TCP socket in cleartext. Wire traffic captured between two local daemons confirms that post-handshake transport frames carry no authentication tags or stream ciphers, with frame layouts beginning with raw Radicle protocol magic byte sequences followed directly by unencrypted Git packfile headers. Alongside unencrypted transmission, the connection handshake contains an authentication validation flaw that lets attackers forge a connection by presenting a spoofed Node ID associated with an allow-listed peer, meaning an on-path eavesdropper can passively capture valid Node IDs transmitted in cleartext and then exploit the authentication defect to impersonate authorized peers and pull private repositories directly from seed nodes.
The core defect originates from an architectural mismatch between transport setup and frame dispatching in the underlying Rust repository, Heartwood. During initialization, the network state machine processes the Noise handshake, but the framing layer skips encryption routines during write calls. The report notes that Git content integrity remains intact because Git objects are content-addressed and references are cryptographically signed, meaning an attacker can't modify repository contents without invalidating signatures, but transport confidentiality is absent. Software teams using Radicle must treat all private repositories cloned, pushed, or seeded across clearnet connections as compromised, and engineering leads should immediately rotate any cryptographic tokens, credentials, or production secrets stored within those repositories.
Until patched binaries are released, teams must restrict node operations to isolated overlay networks, with operators able to configure encrypted WireGuard tunnels or SSH port forwarding between authorized hosts. The maintainers confirmed that the custom Noise transport layer will be completely abandoned in favor of Iroh, an open-source peer-to-peer networking stack built atop QUIC and TLS. Because current node releases lack protocol version negotiation fields inside handshake frames, introducing an encrypted framing patch on the existing wire structure is impossible without causing connection crashes, and the transition to Iroh will break network backward compatibility entirely, causing a hard network partition between legacy 1.x installations and upgraded nodes once the new major release becomes available. The decision to scrap the existing transport architecture rather than patch it reflects the severity of the protocol design gap and the technical impossibility of retrofitting encryption without breaking every existing deployment. Organizations running decentralized code collaboration infrastructure face a stark choice between operational continuity and security, a tension that will only resolve when the architectural overhaul ships and teams complete what amounts to a forced migration.

