Radicle’s peer-to-peer protocol ships private repos in cleartext and lets nodes impersonate each other
On 23 September 2026, Radicle disclosed that its peer-to-peer protocol — present in every version ever released — transports data in cleartext and accepts node impersonation during the connection handshake. Anyone using private repositories should stop seeding them and treat everything already synced over the network as disclosed.
23 September 2026. Radicle, the decentralized peer-to-peer code forge built on Git, discloses two critical flaws in its network protocol. Every version. Both flaws affect every version released to date. Transport, not storage. They live in the transport layer between nodes, not in the data model: Git objects and Signed References remain verified, so an attacker cannot forge code or identities. Why it matters: what is broken is confidentiality and authentication — and the only fix is a breaking migration, with no backward compatibility.
Two flaws that compound each other
The first flaw is easy to state: traffic between two Radicle nodes is neither encrypted nor authenticated. Objects travel in cleartext. Anyone positioned on the network path between two syncing nodes can read everything they exchange. It was reported on 24 June 2026 by Konstantinos Maninakis, who published his analysis on his blog; Radicle passed it upstream to the netservices.rs repository at cyphernet-labs.
The second flaw sits in the handshake. Peer authentication is broken and allows impersonation: an attacker can connect to a node presenting a Node ID that is not its own. Private repositories are shared only with an allow-list of Node IDs. An attacker who fakes an allowed ID can therefore fetch a private repository directly, without even being on the network path. This second issue was reported on 12 August 2026 by the researcher cryptocode, with a fix proposed upstream in cyphernet.rs.
Each flaw has limits on its own. To impersonate an allowed Node ID, you must first know one, and the allow-list is not public: an attacker off the path has to guess. It is combined that the two flaws become genuinely exploitable. An attacker on the path sees the Node IDs at both ends of a connection — both normally on the allow-list. They read whatever is exchanged while they watch, then reuse a Node ID they saw to pull the entire repository on demand.
Integrity holds, confidentiality collapses
It is worth being precise about what stays safe, because it is counter-intuitive. The Signed References signatures still detect any object modified in transit. If an attacker tampers with a file on the wire, the receiving node notices and rejects the object. The threat is therefore not code poisoning but reading. For a public repository, information leakage is secondary — the content is public by definition. For a private repository, the reverse is true: transport encryption is precisely the guarantee that collapses.
That is also why the usual workarounds are not enough. Radicle states it plainly in its advisory: routing through Tor, I2P, a VPN or any other overlay network does not protect you. Those layers hide traffic from an observer on the path, which shrinks the attack surface, but they do not stop peer impersonation. A targeted, sophisticated attack can still exfiltrate the contents of a private repository. The realistic threat is anyone on the path between your node and the one it syncs with — and no setting or allow-list protects against it.
What to do right now
The fix does not exist yet, and Radicle is deliberately publishing the advisory before it: no fix released later can undo an exposure that has already happened. The guidance is therefore defensive, immediate and unambiguous.
Stop seeding private repositories. rad block <RID> sets an explicit block on a repository, safer than rad unseed: if you changed the default seeding policy from block to allow, an unseed leaves your node still serving the repository, whereas block is checked first.
# List private repositories in storage
rad ls --private --all
# Explicitly block seeding of each private repository
rad block <RID>
# Or stop the node entirely
rad node stop Treat everything already synced as disclosed. Every private repository that has already crossed the network must be considered exposed. If it contained unencrypted credentials, keys or tokens, rotate them.
Notify authorized peers. Blocking does not reach copies already fetched by peers: their nodes carry the same flaws. Ask them to block the repository in turn. And blocking does not erase your local copy — it stays in $(rad path)/storage/, which is what you want if you plan to resume seeding once a fixed version ships.
A breaking migration, and what it says about the design
The reason there is no backward-compatible fix comes down to the absence of version negotiation in the current protocol: the fix is incompatible on the wire, so something has to break. Radicle announces it will replace its network protocol — today a custom protocol built on Noise — with iroh, an open source peer-to-peer networking stack built on open standards. Beyond the flaws, iroh brings NAT traversal, which improves the reliability and resilience of the network.
The switch will partition the network into two clusters that can no longer talk to each other: migrated nodes and non-migrated nodes. The project is working to contain the breakage to the network layer, keeping the storage layout compatible to smooth the upgrade path. That is the price of an early design decision: not negotiating a protocol version means condemning yourself to a clean break the day the protocol has to change.
Verdict
If you host private repositories on Radicle, stop seeding them immediately — rad block on each — rotate every secret they contain and treat everything already synced as disclosed: no future fix rewinds the clock. If you sync other people’s private repositories, apply the same rule and warn the other peers, because their nodes are just as vulnerable as yours. If you only use Radicle for public code, the risk is low — object integrity is preserved by Signed References — but watch for the major release, because the migration to iroh will force you to upgrade to stay on the network. The lesson goes beyond Radicle: a peer-to-peer protocol with no encryption and no version negotiation is not repaired, it is replaced.