A vulnerability in Bitcoin Core allows miners to run code on others' nodes, with about 43% of nodes still unpatched

By: rootdata|2026/05/06 11:50:23
0
Share
copy

According to Protos, btc-42">Bitcoin Core developers recently disclosed a high-risk vulnerability numbered CVE-2024-52911, which affects versions 0.14.1 to 28.4, allowing miners to remotely crash other users' nodes and execute code by mining specially crafted blocks.

The vulnerability was discovered and responsibly disclosed by developer Cory Fields in November 2024. The fix was merged in December of that year and released with version v29 in April 2025. The last vulnerable 28.x version series was discontinued on April 19, 2026.

However, since upgrading Bitcoin full nodes is voluntary, it is estimated that about 43% of nodes are still running the vulnerable old version software, facing potential risks. Fortunately, the cost of implementing such an attack is extremely high—miners would need to allocate significant computational power to mine invalid blocks that do not yield block rewards—so it is likely that it has never been exploited in practice.

You may also like

ZachXBT: Humanity private key leak and abnormal surge in H token should be viewed separately

On June 9, according to related disclosures, on-chain investigator ZachXBT posted an update on Humanity’s roughly $31 million security incident, saying that after further analyzing fund flows, he currently tends to believe the project team was not involved in an “inside job” or a self-staged attack. According to him, the official explanation about the private key leak was broadly accurate, but before the token unlock, the price of H had been artificially pushed higher, and the hacker later took advantage of that market environment; therefore, the private key leak and the earlier abnormal price pumping should be regarded as two separate and independent events. This reframing has shifted the market’s understanding of the nature of the incident. Earlier discussion around Humanity had focused on whether the team directly participated in the attack or used the security incident to cover up internal operations. ZachXBT’s latest remarks shift the focus from “whether it was self-theft” to “whether there were pre-unlock market structure issues.” He also questioned whether the team may have.

Morning Report | OpenAI has submitted an S-1 registration statement draft to the U.S. SEC; Morpho completes $175 million financing

Overview of Important Market Events on June 9th

Morning Report | BitMine increased its holdings by 126,971 ETH last week; trader Eugene announced his exit from the crypto market

Overview of Important Market Events on June 8th

Wang Chuan: How can one not feel anxious after the neighbor Old Wang made thirty times profit by investing in storage stocks? (Seven) - A quarter-century cycle

In-depth analysis of the "reflexivity" bubble trap in storage stocks: Beware of the backlash from the bullwhip effect and the false narrative of high growth; do not let the short-term myth of wealth become a wealth abyss that cannot be recovered for 25 years.

Cryptocurrency CEXs are flocking to sell US stocks, and traditional brokerages are facing an "uninvited guest."

The major reshuffle has just begun.

$75 billion in foreign capital has fled, and South Korean retail investors have absorbed it all using leverage

Despite the accelerated migration of Korean funds from cryptocurrency to the stock market, the Korean market remains an important barometer for global cryptocurrency retail liquidity and recovery turning points.

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com