Bitcoin Core's First Memory Safety Bug Exposed: 43% of Nodes Unpatched, Miners Could Execute Remote Code

Bitcoin Core's First Memory Safety Bug Exposed: 43% of Nodes Unpatched, Miners Could Execute Remote Code

N
News Editor 01
2026-07-22 19:20:13
Bitcoin Core disclosed its first memory safety vulnerability CVE-2024-52911, allowing miners to remotely crash nodes and execute code. An estimated 43% of nodes remain on unpatched versions.
Bitcoin Corememory safety vulnerabilityCVE-2024-52911node upgradeUse-After-Free

Bitcoin Core has disclosed its first-ever memory safety vulnerability (CVE-2024-52911), located in the validation engine. The flaw enables a miner to remotely crash a peer's full node and potentially execute arbitrary code by mining a specially crafted block. Industry estimates suggest approximately 43% of Bitcoin Core nodes are still running vulnerable software versions.

Attack Mechanism: High Cost, Simple Principle

The bug affects Bitcoin Core versions 0.14.1 through 28.4 and was discovered by developer Cory Fields in November 2024. During block validation, Bitcoin Core precomputes and caches transaction input data, then dispatches script verification tasks to background threads. Under CVE-2024-52911, a node may continue reading cached memory contents after that memory has been freed and repurposed — a classic Use-After-Free exploit. While the attack concept is straightforward, executing it is extremely costly: the attacker must be a miner and dedicate substantial hashrate to mine invalid special blocks that yield no block reward, burning significant electricity and opportunity cost every minute.

Bitcoin Core Developers: First Memory Safety Issue

In its advisory, Bitcoin Core acknowledged that remote code execution (RCE) is theoretically possible but provided no confirmed instances. Officials stressed that due to the high cost, the long exposure window, and limitations in block data, it is unlikely miners have widely exploited this bug. Core developer Niklas Gögge wrote on X: "We've been publishing Bitcoin Core security advisories for about two years now, and (as far as I'm aware) we just disclosed our first memory safety issue: a Use-After-Free in the validation engine. Thanks to Cory Fields of DCI for finding and reporting it." Node upgrades are voluntary and not automatic, leaving a significant portion of the network running outdated versions.

Responsible Disclosure: A Year and a Half of Quiet Patching

Cory Fields privately reported the bug in November 2024. Four days later, Bitcoin Core developer Pieter Wuille submitted a fix via PR 31112, titled "Improve parallel script validation error debug logging" — a deliberately mundane maintenance update to avoid drawing attention. The PR was reviewed and merged in December 2024, and the fix shipped in Bitcoin Core 29.0 in April 2025. The last vulnerable branch, 28.x, reached end-of-life (EOL) on April 19, 2026. After giving node operators ample time to upgrade, Bitcoin Core publicly disclosed the vulnerability details this week. The Bitcoin consensus rules remain unaffected by this fix. The vulnerability existed in the node software's memory checking mechanisms, and the patch is included in Bitcoin Core v29 and later.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.