Open account

Bitcoin Core CVE-2024-52911 Allowed Miners to Crash Nodes, Execute Remote Code

Latest reports on CVE-2024-52911 reveal Bitcoin Core's use-after-free bug (v0.14.1–28.4) enabled miners to crash nodes or potentially execute remote code via costly invalid blocks, with ~43% of nodes still vulnerable on pre-v29.0 software. Discovered November 2024 by Cory Fields, fixed covertly in December 2024 and shipped in v29.0 (April 2025), the flaw was publicly disclosed May 5, 2026, post-28.x EOL on April 19. No exploits observed due to high attack costs forfeiting rewards; operators urged to upgrade amid low systemic price risk but elevated stability concerns.

Category

Bitcoin

Sentiment

Neutral

Event

Security incident

Reading time

1 min