CVE-2010-5139General(bitcoin / bitcoin_core)

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch bitcoin bitcoin_core systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bitcoins via a crafted Bitcoin transaction.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-189

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bitcoin_core
  • wxbitcoin

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 48 mentions across 31 observed days

What's happening

  • Active exploitation reported across 13 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 19 signals
  • General: 25 classified signals
  • Disclosure: 9 classified signals
  • Peaked 29d ago at 10 mentions (2026-02-02); latest day: 1
  • 48 total mentions across 31 days

Affected systems

Vendors
Products
bitcoin_corewxbitcoin

3 versions affected across 2 products

Deep dive

Activity timeline48 mentions / 31d
035810Mentions · 2026-01-28: 1Mentions · 2026-02-02: 10Mentions · 2026-02-03: 6Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-12: 1Mentions · 2026-02-19: 1Mentions · 2026-03-04: 1Mentions · 2026-03-08: 1Mentions · 2026-03-17: 2Mentions · 2026-04-08: 1Mentions · 2026-04-14: 1Mentions · 2026-04-16: 3Mentions · 2026-04-17: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-05-04: 1Mentions · 2026-05-23: 1Mentions · 2026-06-20: 1Mentions · 2026-07-06: 1Mentions · 2026-07-11: 1Mentions · 2026-07-25: 1Mentions · 2026-07-31: 1Mentions · 2026-08-03: 1Mentions · 2026-08-06: 1Mentions · 2026-08-13: 1Mentions · 2026-08-23: 1Mentions · 2026-09-09: 1Mentions · 2026-09-18: 1Mentions · 2026-09-24: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-09-18: 1Active Exploitation · 2026-02-02: 6Active Exploitation · 2026-02-03: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-09-18: 1Patch / Workaround · 2026-02-02: 4Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-07-25: 1Patch / Workaround · 2026-07-31: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-09-09: 1Patch / Workaround · 2026-09-18: 1Technical Details · 2026-02-02: 7Technical Details · 2026-02-03: 2Technical Details · 2026-02-12: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-17: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-22: 1Technical Details · 2026-07-31: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-23: 1Technical Details · 2026-09-09: 1Technical Details · 2026-09-18: 101-2802-0402-1903-1704-1604-2306-2007-2508-0609-0910-02
Signal classification4 categories
General
2553.2%
Disclosure
919.1%
Patch
714.9%
Active Exploitation
612.8%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-01-281
General1
2026-02-0210
Active Exploitation2Disclosure6Patch2
2026-02-036
Active Exploitation1Disclosure1General4
2026-02-041
General1
2026-02-051
General1
2026-02-121
Patch1
2026-02-191
General1
2026-03-041
General1
2026-03-081
Patch1
2026-03-172
General1Patch1
2026-04-081
General1
2026-04-141
Disclosure1
2026-04-163
General3
2026-04-171
General1
2026-04-221
Active Exploitation1
2026-04-231
General1
2026-05-041
General1
2026-05-231
General1
2026-06-201
Patch1
2026-07-061
General1
2026-07-111
General1
2026-07-251
Patch1
2026-07-311
General1
2026-08-031
Active Exploitation1
2026-08-061
General1
2026-08-131
General1
2026-08-231
General1
2026-09-091
Disclosure1
2026-09-181
Active Exploitation1
2026-09-241
General1
Full discourse20 posts
  • Patrick L Riley@Acquired_Savant
    Disclosure

    Bitcoin has had two previously known code exploits where someone could "mint infinite free bitcoin" for themselves. The CVE-2010-5139 bug was announced on 2010-8-15, it minted 184 Billion BTC, and required a Bitcoin chain roll-back. The CVE-2018-17144 bug was announced on 2018-09-17 and was discovered by a BitcoinCash developer, who disclosed it instead of exploiting it. This isn't a new trick. Naked shorts, paper Silver and Gold, Jeffery Epstein's money printer, AKA Bitcoin. P.S. at the time Jeffery Epstein invested in the Bitcoin Foundation ($850,000 known) Bitcoin was only worth $225.

    Post summary

    The post references two historical Bitcoin CVEs that enabled minting of infinite BTC, noting their discovery dates and basic impact details.

    4824332971346354.4K
    10.7K followersView on X
  • Çetin Kaya Koç@cetinkayakoc
    Active Exploitation

    Bitcoin'in daha önce bilinen iki kod açığı vardı; bu açıklar sayesinde birileri kendisi için "sonsuz sayıda ücretsiz Bitcoin basabiliyordu". CVE-2010-5139 hatası 15 Ağustos 2010'da duyuruldu, 184 milyar BTC bastı ve Bitcoin zincirinin geri alınmasını gerektirdi. CVE-2018-17144 hatası ise 17 Eylül 2018'de duyuruldu ve bir BitcoinCash geliştiricisi tarafından keşfedildi; geliştirici bu açığı istismar etmek yerine ifşa etti. Bu yeni bir numara değil. Jeffery Epstein'ın para basma makinesi, yani Bitcoin. Not: Jeffery Epstein Bitcoin Vakfı'na yatırım yaptığında (bilinen 850.000 dolar) Bitcoin'in değeri sadece 225 dolardı.

    Post summary

    The post reports two Bitcoin-related CVEs, noting that CVE‑2010‑5139 was actively exploited to mint 184 billion BTC, while CVE‑2018‑17144 was disclosed but not exploited.

    96242414542.7K
    66.2K followersView on X
  • Luke Dashjr@LukeDashjr
    Patch

    CVE-2010-5139 was fixed with a retroactive soft fork - 52 blocks worth over 2600 BTC to miners were WIPED OUT from history, and any transactions confirmed in that time were reversible. It could have been fixed by simply voiding the UTXOs with the inflation, no reorg needed. But that would have been an actually bad precedent, and is NOT a viable solution to CSAM. BIP110 is great because it avoids even the retroactive fix - by patching the bugs proactively, we can avoid ever having to roll back ANY blocks. Miners don't properly appreciate that by failing to activate it sooner, they have been playing with fire.

    Post summary

    The post explains that CVE-2010-5139 was remedied with a retroactive soft fork wiping out miners’ rewards and suggests the proactive BIP110 patch to avoid such rollbacks.

    231315744.5K
    104.6K followersView on X
  • Patrick L Riley@Acquired_Savant
    Disclosure

    Bitcoin has had TWO "inflation bugs", where someone could "mint infinite free bitcoin" for themselves. (Bookmark this); Here they are: 1. The CVE-2010-5139 bug was announced on 2010-8-15, it minted 184 Billion BTC, and required a Bitcoin chain roll-back!! 2. The CVE-2018-17144 bug was announced on 2018-09-17 and was discovered by a BitcoinCash developer, who disclosed it instead of exploiting it.

    Post summary

    The post highlights two Bitcoin inflation bugs—CVE‑2010‑5139 that minted 184 Billion BTC and required a chain rollback, and CVE‑2018‑17144 disclosed by a developer. No PoC, exploit code, patch, or false‑positive claim is provided.

    410172141.7K
    10.7K followersView on X
  • ⬣Hexlena PulseAlot⬣@StakeHEX5555
    Patch

    Look what they need to mimic a fraction of our power. Lolz #Bitcoin Hex 0.1.0 (2019) Bitcoin 0.1.0 (2009) 0.1.5 0.3.0 0.3.10 and earlier — Affected by value overflow incident (CVE-2010-5139 / "hack"): Exploit on August 15, 2010 created ~184 billion invalid BTC via integer overflow. 0.3.11 — Fix for value overflow incident (CVE-2010-5139): Added checks to reject overflowing transactions; soft fork resolved the issue quickly. 0.3.21 0.5.0 0.6.0 0.7.0 0.8.0 0.9.0 0.10.0 0.11.0 0.11.1 0.11.2 0.12.0 0.12.1 0.13.0 0.13.1 0.13.2 0.14.0 0.14.1 0.14.2 — Affected by inflation/DoS bug (CVE-2018-17144): Duplicate input flaw could enable inflation or crashes. 0.14.3 — Partial backport/fix elements for CVE-2018-17144. 0.15.0 0.15.0.1 0.15.1 0.15.2 — Partial fix backport for CVE-2018-17144. 0.16.0 0.16.1 0.16.2 — Affected by inflation/DoS bug (CVE-2018-17144): Critical risk of supply inflation if exploited. 0.16.3 — Fix for CVE-2018-17144: Patched to prevent inflation/crashes; urgent release 0.17.0 0.17.0.1 0.17.1 0.18.0 0.18.1 0.19.0.1 0.19.1 0.20.0 0.20.1 0.20.2 0.21.0 0.21.1 0.21.2 0.22.0 0.22.1 0.23.0 0.23.1 0.23.2 0.24.0.1 0.24.1 0.24.2 0.25.0 0.25.1 0.25.2 0.26.0 0.26.1 0.26.2 0.27.0 0.27.1 0.27.2 0.28.0 0.28.1 0.28.2 0.28.3 0.29.0 0.29.1 0.29.2 0.29.3 (released February 10, 2026) — Bug fixes, performance improvements 0.30.0 0.30.1 0.30.2 (most recent as of February 12, 2026)

    Post summary

    The message lists Bitcoin releases, cites CVE‑2010‑5139 and CVE‑2018‑17144, documents historical exploitation via integer overflow, and details the patches that resolved these vulnerabilities.

    3964732.8K
    773 followersView on X
  • palmer.eth@garypalmerjr
    Disclosure

    Bitcoin has had TWO "inflation bugs", where someone could "mint infinite free bitcoin" for themselves. (Bookmark this); Here they are: 1. The CVE-2010-5139 bug was announced on 2010-8-15, it minted 184 Billion BTC, AND, actually required a Bitcoin chain roll-back!! 2. The CVE-2018-17144 bug was announced on 2018-09-17 and was discovered by a BitcoinCash developer, who disclosed it instead of exploiting it!

    Post summary

    The post lists two Bitcoin inflation bugs—CVE‑2010‑5139, which was exploited to mint 184 Billion BTC requiring a chain rollback, and CVE‑2018‑17144, which was discovered and disclosed but not exploited.

    4421772.7K
    17.1K followersView on X
  • محمد المصري@EgyHashX
    Active Exploitation

    الـ PoW هي مجرد خوارزمية إجماع، لا بتأثر على لا مركزية الشبكة ولا بتأثر على أمنها. البتكوين اللي بيستخدم الـ "PoW" تم اختراقه وسك 184 مليار عملة (CVE-2010-5139)، حصل عليه Double Spending، كان فيه ثغرات لإنشاء بتكوين جديد وكسر حاجز 21 مليون (CVE-2018-17144) كان فيه ثغرات كافية تقتل الشبكة (INVDoS) إلخ.

    Post summary

    The post alleges that Bitcoin, using PoW, has been exploited via CVE‑2010‑5139 and CVE‑2018‑17144, leading to double spending and loss of 184 billion coins, but offers no concrete evidence, patches, or PoC details.

    1012158.0K
    38.8K followersView on X
  • 윤회엔딩@EndTheKarma
    Disclosure

    비트코인에는 이전에 누군가가 "무한히 무료 비트코인을 발행"할 수 있는 두 가지 코드 취약점이 알려진 바 있습니다. CVE-2010-5139 버그는 2010년 8월 15일에 발표되었으며, 1840억 BTC의 비트코인을 발행했고, 비트코인 ​​체인 롤백을 필요로 했습니다. CVE-2018-17144 버그는 2018년 9월 17일에 발표되었으며, 비트코인캐시 개발자가 이를 발견하여 악용하는 대신 공개했습니다. 이건 새로운 수법이 아닙니다. 엉터리 반바지, 종이로 만든 은과 금, 제프리 엡스타인의 돈 찍어내는 기계, 일명 비트코인. 추신: 제프리 엡스타인이 비트코인 ​​재단에 투자했을 당시(알려진 바에 따르면 85만 달러) 비트코인 ​​가격은 겨우 225달러였습니다.

    Post summary

    The post references two historic Bitcoin vulnerabilities, CVE‑2010‑5139 and CVE‑2018‑17144, noting their impact and discovery details, but it does not discuss any current exploitation, patches, or proof‑of‑concepts.

    170182916
    3.5K followersView on X
  • ambitious man .. طموح شاب@Ambitiousman0
    General

    المعلومة الثانية سبق أن تعرض البيتكوين لثغرتين خطيرتين: 1️⃣ CVE-2010-5139 سمحت بسكّ 184 مليار بيتكوين استدعت إعادة السلسلة 2️⃣ CVE-2018-17144 اكتشفها مطور من Bitcoin Cash وتم الإفصاح عنها بدل استغلالها ⚠️هاد الشخص او المنظمة كانوا حرفياً بيستغلوا كل شي ممكن يربح او يدخل اموال عليهم و عالناس من حولهم ...!!

    Post summary

    The post lists two historic Bitcoin CVEs and briefly describes their impact, but offers no details on PoC, exploitation tools, active attacks, patches, or technical specifics.

    100150712
    22.3K followersView on X
  • Patrick L Riley@Acquired_Savant
    Disclosure

    Either of these could have minted unknown amounts of free Bitcoin. The CVE-2010-5139 bug was announced on 2010-8-15, it minted 184 Billion BTC, and required a Bitcoin chain roll-back. The CVE-2018-17144 bug was announced on 2018-09-17 and was discovered by a BitcoinCash developer, who disclosed it instead of exploiting it.

    Post summary

    The text outlines two Bitcoin-related CVEs, noting their announcement dates and potential to mint large amounts of BTC, yet it offers no evidence of exploitation, PoC, or mitigation.

    1101111.5K
    10.7K followersView on X
  • James@blurry_omen
    General

    @grok For the following versions of Bitcoin Core, label them as “Minted more coins” or “double spend” - if an upgrade in mining software, allowed people to do one of those: CVE-2018-17144 CVE-2010-5139 Were they resolved because the 6 Bitcoin core developers work in good faith (Yes or No)? If they worked in bad faith could they create more BTC, or enable double spending (Yes or No)? How are the developed selected? Is there any real reason they couldn’t be nefarious (Yes or No) -one word answers where possible. One sentence where not. Reference what you’re responding too.

    Post summary

    The tweet poses questions about two CVEs but provides no factual information, usage claims, or technical details.

    200712.1K
    174 followersView on X
  • Fabricio Sasaki@Fabricio_Sasaki
    Patch

    Email do Epstein em 2015 conhecendo os criadores russos do Bitcoin, onde pediu para colocar uma vulnerabilidade de propósito por 1 bilhão de dólares. Essa falha foi descoberta e corrigida anos depois de alguém criar 15 bilhões. Permitia criar bitcoin do nada. CVE-2010-5139 https://t.co/24nwso2iAZ

    Post summary

    The tweet notes that CVE-2010-5139 was discovered and later patched, with no indication of a PoC or active exploitation.

    10162351
    446 followersView on X
  • Bitcoin Butlers@bitcoinbutlers
    General

    @JWWeatherman_ @SeedSigner CVE-2010-5139, CVE-2018-17144, CVE-2013-3220, CVE-2012-2459, CVE-2011-4447 and you only said no to part of the issue raised - single point of failure, OP also references merely one potential part of a quorum.

    Post summary

    The tweet merely lists several CVEs and notes a single point of failure concern, but offers no technical details, exploits, patch information, or evidence of active use.

    00160223
    764 followersView on X
  • Grok@grok
    Active Exploitation

    Yes, Bitcoin had a blockchain rollback in August 2010 due to the CVE-2010-5139 bug, which allowed creation of 184 billion invalid BTC. The chain was forked to exclude the exploit. Another potential inflation bug (CVE-2018-17144) in 2018 was patched before exploitation, without a rollback.

    Post summary

    Bitcoin’s CVE‑2010‑5139 resulted in a blockchain rollback after an inflation exploit that created invalid BTC, while CVE‑2018‑17144 was patched before exploitation.

    10040690
    8.1M followersView on X
  • Grok@grok
    General

    CVE-2018-17144 (Bitcoin Core disclosure): double spend CVE-2010-5139 (NVD): Minted more coins Resolved because good faith: Yes (team fixed bugs promptly). Bad faith: No (network consensus by miners/nodes required; devs can't force rules). Developers selected: merit via open-source contributions. Real reason couldn’t be nefarious: Yes (decentralized economic incentives).

    Post summary

    The post names two CVEs and gives only high‑level statements about Bitcoin Core without any technical vulnerability or exploit details.

    000311.4K
    8.7M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2010-5139 2 - CVE-2025-21042 3 - CVE-2025-55177 4 - CVE-2025-13292 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers without providing additional details such as exploit code, patches, or technical specifics.

    10030250
    1.7K followersView on X
  • Obey 126@OBEY_126
    Active Exploitation

    The 2010 Value Overflow Bug (CVE-2010-5139) Status: Exploited Date: August 15, 2010 Impact: An attacker successfully created 184,467,440,737 BTC in a single transaction due to an integer overflow bug. Resolution: Satoshi Nakamoto and other developers released a fix within hours. The network performed a rollback (fork) to invalidate the bad transaction. This remains the only time Bitcoin's monetary supply was actually violated on the main chain.

    Post summary

    CVE-2010-5139 was actively exploited to inflate the Bitcoin supply, but the flaw was quickly patched via a network fork and developer fix.

    1002046
    1.1K followersView on X
  • ₿rad@BradSanJuan
    Patch

    @BitcoinGambit @design_sats @WhalesSecret @derekmross CVE-2010-5139 is officially cataloged as a software vulnerability, not a breach. The fix was a code patch, the standard response to a bug, and no security boundary was crossed. Yet to you it's a hack. I can live with that. Have a nice day, John!

    Post summary

    The post confirms that CVE‑2010‑5139 was addressed with a code patch and clarifies it was merely a software vulnerability rather than a breach.

    1002035
    3.4K followersView on X
  • zooko🛡🦓🦓🦓 ⓩ@zooko
    General

    @robustus @ambimorph Which means they both fall into the same category as the two known Bitcoin counterfeiting bugs—CVE-2010-5139 and CVE-2018-17144—i.e. immediately detectable by any member of the public. ⤵️

    Post summary

    The tweet references two known Bitcoin counterfeiting CVEs and notes they are easily detectable by the public, but provides no technical details, PoC, or exploitation evidence.

    10020173
    111.3K followersView on X
  • Grok@grok
    General

    Evet, CVE-2010-5139 (15 Ağustos 2010) 184 milyar BTC yarattı ve zincir geri alınarak düzeltildi. CVE-2018-17144 (17 Eylül 2018) enflasyon açığına yol açabilirdi, Bitcoin Cash geliştiricisi dahil ekiplerce ifşa edildi, istismar edilmedi. Epstein, 2015'te (BTC ~225$) MIT'ye 525 bin dolar bağışladı, bu Bitcoin geliştiricilerini destekledi; ancak Bitcoin Vakfı'na doğrudan 850 bin dolar yatırım doğrulanmadı. Komplo iddiaları kanıtsız.

    Post summary

    The post cites CVE‑2010‑5139 and CVE‑2018‑17144 with alleged impacts and a chain rollback fix, but provides no exploit or PoC evidence and lacks detailed vulnerability data, making it a vague, likely misinformation claim.

    10011491
    8.1M followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appbitcoinbitcoin_core---
Appbitcoinbitcoin_core0.3.4--
Appbitcoinbitcoin_core0.3.5--
Appbitcoinbitcoin_core0.3.8--
Appbitcoinwxbitcoin---
Appbitcoinwxbitcoin0.3.4--
Appbitcoinwxbitcoin0.3.5--
Appbitcoinwxbitcoin0.3.8--

Explore more