Bitcoin News

Story: CVE-2024-52911: Bitcoin Core Miners Could Have Crashed Nodes, Executed Remote Code

By Pankaj K

1 / 15

How the Memory Bug Worked. Bitcoin Core called it a script interpreter crash. Here's what happened during block validation:…

2 / 15

Network Still Exposed. The use-after-free memory bug lived in the validation engine.

3 / 15

Quiet Fix, Public Disclosure. The vulnerability stayed under wraps initially to prevent exploitation while developers worked on…

4 / 15

Bitcoin Core developers just went public with a nasty bug. CVE-2024-52911. Miners could've crashed nodes and run code on them remotely. The flaw sat in versions 0.14.1 through 28.

5 / 15

The attack wasn't cheap, though. A miner wanting to exploit this would need to throw serious hashpower at mining special blocks. And those blocks?

6 / 15

Bitcoin Core called it a script interpreter crash. Here's what happened during block validation: the software cached transaction data, then sent it off to background threads.

7 / 15

The fix landed in version 29 and later releases. But upgrading? That's voluntary. And a lot of nodes haven't bothered.

8 / 15

Fields reported the bug in November 2024. Four days later, Pieter Wuille proposed a fix. The patch got consensus fast and made it into Bitcoin Core 29.0 by April 2025.

9 / 15

The bug didn't mess with Bitcoin's consensus rules. It was all about how node software handled memory.

10 / 15

The use-after-free memory bug lived in the validation engine. When cached transaction data got read after being freed, things went sideways.

11 / 15

Bitcoin Core's disclosure strategy aimed for stability without freaking everyone out. The advisory looked like routine maintenance—just improving script validation error logging,…

12 / 15

But here's the problem: a big chunk of the network still runs old software. That's the headache with decentralized systems.

13 / 15

The attack scenario was unlikely, sure. High cost, complicated setup. But the potential for remote code execution was real, and that posed serious risk to the network.

14 / 15

Disclosure came after thorough review and consensus inside the development community. It took a collaborative effort to keep Bitcoin's infrastructure intact.

15 / 15

Despite the patch being out there, the voluntary upgrade process means part of the network still operates on vulnerable versions.

The Currency Analytics

Want the full story?