CVE-2018-17144General(bitcoin / bitcoin_core)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch bitcoin bitcoin_core systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.

5.5/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bitcoin_core
  • bitcoin_knots

Threat summary

  • Active exploitation appears in 10 classified signals
  • Patch or workaround signal is available
  • 111 mentions across 61 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 10 signals
  • Patch or workaround mentioned in 36 signals
  • Technical details provided in 42 signals
  • General: 64 classified signals
  • Disclosure: 15 classified signals
  • Peaked 30d ago at 14 mentions (2026-06-05); latest day: 1
  • 111 total mentions across 61 days

Affected systems

Products
bitcoin_corebitcoin_knots

Deep dive

Activity timeline111 mentions / 61d
0471114Mentions · 2026-02-02: 12Mentions · 2026-02-03: 6Mentions · 2026-02-05: 1Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-12: 2Mentions · 2026-02-19: 1Mentions · 2026-02-22: 1Mentions · 2026-02-23: 1Mentions · 2026-02-26: 1Mentions · 2026-03-04: 1Mentions · 2026-03-06: 2Mentions · 2026-03-08: 1Mentions · 2026-03-19: 1Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Mentions · 2026-04-16: 2Mentions · 2026-04-17: 2Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-25: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1Mentions · 2026-05-10: 1Mentions · 2026-05-20: 1Mentions · 2026-06-03: 4Mentions · 2026-06-04: 1Mentions · 2026-06-05: 14Mentions · 2026-06-06: 1Mentions · 2026-06-07: 2Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-12: 4Mentions · 2026-06-14: 1Mentions · 2026-06-22: 1Mentions · 2026-06-25: 1Mentions · 2026-07-03: 1Mentions · 2026-07-06: 1Mentions · 2026-07-11: 1Mentions · 2026-07-16: 1Mentions · 2026-07-19: 1Mentions · 2026-07-22: 1Mentions · 2026-07-28: 1Mentions · 2026-07-29: 2Mentions · 2026-07-31: 1Mentions · 2026-08-13: 2Mentions · 2026-08-18: 1Mentions · 2026-08-24: 1Mentions · 2026-08-28: 1Mentions · 2026-09-07: 1Mentions · 2026-09-09: 7Mentions · 2026-09-13: 2Mentions · 2026-09-14: 1Mentions · 2026-09-17: 1Mentions · 2026-09-18: 2Mentions · 2026-09-21: 1Mentions · 2026-09-26: 1Mentions · 2026-09-30: 1Active Exploitation · 2026-02-02: 4Active Exploitation · 2026-02-03: 2Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-09-18: 1Patch / Workaround · 2026-02-02: 5Patch / Workaround · 2026-02-03: 2Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-22: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-06-05: 4Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-14: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-29: 1Patch / Workaround · 2026-07-31: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-09-07: 1Patch / Workaround · 2026-09-09: 2Patch / Workaround · 2026-09-13: 1Patch / Workaround · 2026-09-18: 1Technical Details · 2026-02-02: 7Technical Details · 2026-02-03: 3Technical Details · 2026-02-06: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-22: 1Technical Details · 2026-05-10: 1Technical Details · 2026-06-05: 4Technical Details · 2026-06-07: 1Technical Details · 2026-06-12: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-29: 1Technical Details · 2026-07-31: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-24: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-09: 3Technical Details · 2026-09-13: 2Technical Details · 2026-09-14: 1Technical Details · 2026-09-17: 1Technical Details · 2026-09-18: 102-0202-1903-0804-1605-0106-0506-1407-1608-1309-1309-30
Signal classification5 categories
General
6458.2%
Patch
2119.1%
Disclosure
1513.6%
Active Exploitation
87.3%
False Positive
21.8%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-02-0212
Active Exploitation3Disclosure3False Positive1General2Patch3
2026-02-036
Active Exploitation2Disclosure1General2Patch1
2026-02-051
General1
2026-02-061
Patch1
2026-02-081
General1
2026-02-122
Disclosure1Patch1
2026-02-191
General1
2026-02-221
Patch1
2026-02-231
Patch1
2026-02-261
Disclosure1
2026-03-041
Patch1
2026-03-062
General1Patch1
2026-03-081
Patch1
2026-03-191
General1
2026-03-211
General1
2026-03-221
General1
2026-03-261
False Positive1
2026-03-291
Disclosure1
2026-04-162
General2
2026-04-172
General2
2026-04-211
General1
2026-04-221
Active Exploitation1
2026-04-251
General1
2026-04-301
General1
2026-05-011
General1
2026-05-041
General1
2026-05-101
Patch1
2026-05-201
Disclosure1
2026-06-034
Active Exploitation1General3
2026-06-041
General1
2026-06-0514
Disclosure1General12Patch1
2026-06-061
General1
2026-06-072
Disclosure1General1
2026-06-081
General1
2026-06-091
General1
2026-06-124
General3Patch1
2026-06-141
Patch1
2026-06-221
General1
2026-06-251
General1
2026-07-031
Disclosure1
2026-07-061
General1
2026-07-111
General1
2026-07-161
Disclosure1
2026-07-191
General1
2026-07-221
General1
2026-07-281
General1
2026-07-292
General1Patch1
2026-07-311
General1
2026-08-132
General2
2026-08-181
Patch1
2026-08-241
Patch1
2026-08-281
General1
2026-09-071
Patch1
2026-09-097
General6Patch1
2026-09-132
Disclosure1Patch1
2026-09-141
Disclosure1
2026-09-171
Disclosure1
2026-09-182
Active Exploitation1General1
2026-09-211
General1
2026-09-261
General1
Full discourse20 posts
  • Patrick L Riley@Acquired_Savant
    General

    Bitcoin has had two previously known code exploits where someone could "mint infinite free bitcoin" for themselves. The CVE-2010-5139 bug was announced on 2010-8-15, it minted 184 Billion BTC, and required a Bitcoin chain roll-back. The CVE-2018-17144 bug was announced on 2018-09-17 and was discovered by a BitcoinCash developer, who disclosed it instead of exploiting it. This isn't a new trick. Naked shorts, paper Silver and Gold, Jeffery Epstein's money printer, AKA Bitcoin. P.S. at the time Jeffery Epstein invested in the Bitcoin Foundation ($850,000 known) Bitcoin was only worth $225.

    Post summary

    The post references two historical Bitcoin CVEs, noting their discovery and disclosure without indicating active exploitation, patches, or PoC details.

    4824332971346354.4K
    10.7K followersView on X
  • Çetin Kaya Koç@cetinkayakoc
    Active Exploitation

    Bitcoin'in daha önce bilinen iki kod açığı vardı; bu açıklar sayesinde birileri kendisi için "sonsuz sayıda ücretsiz Bitcoin basabiliyordu". CVE-2010-5139 hatası 15 Ağustos 2010'da duyuruldu, 184 milyar BTC bastı ve Bitcoin zincirinin geri alınmasını gerektirdi. CVE-2018-17144 hatası ise 17 Eylül 2018'de duyuruldu ve bir BitcoinCash geliştiricisi tarafından keşfedildi; geliştirici bu açığı istismar etmek yerine ifşa etti. Bu yeni bir numara değil. Jeffery Epstein'ın para basma makinesi, yani Bitcoin. Not: Jeffery Epstein Bitcoin Vakfı'na yatırım yaptığında (bilinen 850.000 dolar) Bitcoin'in değeri sadece 225 dolardı.

    Post summary

    The text reports two Bitcoin CVEs, highlighting that CVE‑2010‑5139 was actively exploited to mint massive BTC, while CVE‑2018‑17144 was disclosed but not used in the wild.

    96242414542.7K
    66.2K followersView on X
  • Robin Linus@robin_linus
    General

    The Liquid hack is not an argument against privacy features. The cryptography wasn’t broken. A cache was. Bitcoin has had the same class of inflation bug without confidential transactions (CVE-2018-17144).

    Post summary

    The post references CVE-2018-17144, noting it is a cache-related inflation bug, but provides no exploit code, active exploitation evidence, or patch information.

    7240177512.9K
    16.5K followersView on X
  • Luke Dashjr@LukeDashjr
    Disclosure

    @1hmle @dathon_ohm Reminder that Bitcoin Core shipped a much more severe consensus bug that could have *actually* impacted people if exploited _in production_ for 18 months, and then totally mishandled the responsible disclosure! (CVE-2018-17144, v0.14-v0.16.2, 2017 & 2018)

    Post summary

    The tweet highlights that Bitcoin Core shipped a severe consensus bug (CVE‑2018‑17144) for 18 months before disclosure, pointing out mishandled responsibility, but it contains no evidence of exploitation, PoC, or patch details.

    224012051.4K
    102.9K followersView on X
  • Cypherpunk ($CYPH)@cypherpunk
    Active Exploitation

    @ericyakes 1. Please don't bully @mert, we love his bald head. 2. Zcash mining wasn't suspended? Miners just temporarily stopped processing Orchard transactions. Transparent, Sapling, and Sprout pools kept running fine. 3. This literally happened with Bitcoin, see CVE-2018-17144.

    Post summary

    The tweet highlights that CVE‑2018‑17144 was actively exploited in Bitcoin, but provides no further technical or mitigation details.

    3709123.8K
    15.3K followersView on X
  • Patrick L Riley@Acquired_Savant
    Disclosure

    Bitcoin has had TWO "inflation bugs", where someone could "mint infinite free bitcoin" for themselves. (Bookmark this); Here they are: 1. The CVE-2010-5139 bug was announced on 2010-8-15, it minted 184 Billion BTC, and required a Bitcoin chain roll-back!! 2. The CVE-2018-17144 bug was announced on 2018-09-17 and was discovered by a BitcoinCash developer, who disclosed it instead of exploiting it.

    Post summary

    The post announces two Bitcoin inflation bugs, noting discovery dates and impact details, but does not provide PoC, exploit code, patch, or evidence of active exploitation.

    410172141.7K
    10.7K followersView on X
  • Nghi AI@thucnghi07
    Patch

    Bitcoin từng suýt gặp thảm họa chỉ vì một lỗi nhỏ trong “đường may” của hệ thống. Năm 2018, lỗi CVE-2018-17144 trong Bitcoin Core có thể khiến một miner độc hại tạo ra BTC ngoài quy tắc cung tiền. Nhìn bộ trang phục này cũng vậy: corset, denim, ren, crochet và lông thú ghép thành nhiều lớp. Chỉ cần một đường may cấu trúc sai, cả bộ đồ có thể mất form. Bitcoin cũng được xây từ nhiều lớp kiểm tra. Một bước xác thực bị bỏ sót có thể biến lỗi nhỏ thành rủi ro cực lớn. May mắn là lỗi được phát hiện và vá trước khi gây hậu quả nghiêm trọng. Theo bạn, thứ khiến Bitcoin mạnh hơn là code hoàn hảo hay khả năng phát hiện và sửa lỗi nhanh?

    Post summary

    The article discusses CVE-2018-17144 in Bitcoin Core, noting it could allow illicit BTC creation but was discovered and patched before causing serious harm.

    41164168.0K
    11.5K followersView on X
  • Luke Dashjr@LukeDashjr
    Patch

    @satofishi Bitcoin is more than consensus. But I didn't mean Core30, I meant in 2018 when they deployed a softfork in secret with 0% hashrate to fix CVE-2018-17144.

    Post summary

    The author notes that Bitcoin deployed a secret softfork in 2018 to patch CVE-2018-17144.

    3616842.0K
    103.5K followersView on X
  • ⬣Hexlena PulseAlot⬣@StakeHEX5555
    Disclosure

    Look what they need to mimic a fraction of our power. Lolz #Bitcoin Hex 0.1.0 (2019) Bitcoin 0.1.0 (2009) 0.1.5 0.3.0 0.3.10 and earlier — Affected by value overflow incident (CVE-2010-5139 / "hack"): Exploit on August 15, 2010 created ~184 billion invalid BTC via integer overflow. 0.3.11 — Fix for value overflow incident (CVE-2010-5139): Added checks to reject overflowing transactions; soft fork resolved the issue quickly. 0.3.21 0.5.0 0.6.0 0.7.0 0.8.0 0.9.0 0.10.0 0.11.0 0.11.1 0.11.2 0.12.0 0.12.1 0.13.0 0.13.1 0.13.2 0.14.0 0.14.1 0.14.2 — Affected by inflation/DoS bug (CVE-2018-17144): Duplicate input flaw could enable inflation or crashes. 0.14.3 — Partial backport/fix elements for CVE-2018-17144. 0.15.0 0.15.0.1 0.15.1 0.15.2 — Partial fix backport for CVE-2018-17144. 0.16.0 0.16.1 0.16.2 — Affected by inflation/DoS bug (CVE-2018-17144): Critical risk of supply inflation if exploited. 0.16.3 — Fix for CVE-2018-17144: Patched to prevent inflation/crashes; urgent release 0.17.0 0.17.0.1 0.17.1 0.18.0 0.18.1 0.19.0.1 0.19.1 0.20.0 0.20.1 0.20.2 0.21.0 0.21.1 0.21.2 0.22.0 0.22.1 0.23.0 0.23.1 0.23.2 0.24.0.1 0.24.1 0.24.2 0.25.0 0.25.1 0.25.2 0.26.0 0.26.1 0.26.2 0.27.0 0.27.1 0.27.2 0.28.0 0.28.1 0.28.2 0.28.3 0.29.0 0.29.1 0.29.2 0.29.3 (released February 10, 2026) — Bug fixes, performance improvements 0.30.0 0.30.1 0.30.2 (most recent as of February 12, 2026)

    Post summary

    The text documents historical Bitcoin version vulnerabilities (CVE-2010-5139 and CVE-2018-17144), noting their exploitation in 2010 and 2018, and lists the corresponding patches and fixes that were released to mitigate them.

    3964732.8K
    773 followersView on X
  • Grok@grok
    False Positive

    No, the claim of two intentional backdoors in Bitcoin Core code isn't accurate based on available records. Major vulnerabilities include the 2010 value overflow bug (allowing invalid BTC creation) and the 2018 inflation bug (CVE-2018-17144), but these were accidental flaws, not deliberate backdoors. They've been fixed. Bitcoin's open-source nature allows ongoing audits.

    Post summary

    The post refutes claims of intentional backdoors in Bitcoin Core, clarifying that the mentioned CVEs were accidental flaws that have been fixed, and notes that ongoing open‑source audits continue to monitor the code.

    1005312.3K
    8.1M followersView on X
  • Jeremiah@jeremiahrogers
    General

    How is what Zcash did substantively different than Bitcoin Core's response to CVE-2018-17144? https://t.co/NAVOYMvOu8

    Post summary

    The tweet merely poses a question about how Zcash’s response to CVE-2018-17144 compares to Bitcoin Core’s, without sharing any further technical or exploit information.

    6303953.7K
    2.0K followersView on X
  • palmer.eth@garypalmerjr
    Disclosure

    Bitcoin has had TWO "inflation bugs", where someone could "mint infinite free bitcoin" for themselves. (Bookmark this); Here they are: 1. The CVE-2010-5139 bug was announced on 2010-8-15, it minted 184 Billion BTC, AND, actually required a Bitcoin chain roll-back!! 2. The CVE-2018-17144 bug was announced on 2018-09-17 and was discovered by a BitcoinCash developer, who disclosed it instead of exploiting it!

    Post summary

    The post reports the announcements of two Bitcoin inflation bugs, noting their discovery dates and brief technical aspects but no exploitation or patch information.

    4421772.7K
    17.1K followersView on X
  • ₿asset 丰🏴‍☠️@SymbianSyMoh
    General

    تخيل تبقي حمار و غبي في نفس الوقت، اي شئ في عالم الرياضيات المعقدة والتشفير ممكن يبقي فيه bugs وخصوصاً ال inflation bugs دي؛ حصلت في بتكوين قبل كده علي فكرة CVE-2018-17144، الفكرة مش إنها تحصل من عدمه إنما لما بتحصل ايه اللي يحصل بعدها؟ هل اقدر اجاوب علي أسئلة زي: - هل تم استغلالها ولا لا؟ - هل في حد أقصي للمعروض والاهم إنه "قابل للتحقق"؟ - هل اقدر اتحقق من ال pools solvency لو حصل لأي واحده فيهم اي ضرر؟ - الخ... إنما ترمي مقارنات يمين وشمال ده مش بس هيخلي الموقف أسوأ، لا، وهيبين قد ايه إن انت مبتفهمش حاجه وده الجزء اللي هيزعلك وهيتعب نفسيتك اكتر، واعتقد إن سعر zec اللي نزل اكتر من ٤٤٪ ف ساعات بيعكس ده، المشكلة ف zec مشكلة ثقه مش مجرد ai model لقي inflation bug!

    Post summary

    The text raises questions about CVE-2018-17144 in Bitcoin but provides no concrete evidence of exploitation, patches, or technical details, thus it falls into a general informational category.

    1311983.4K
    33.5K followersView on X
  • محمد المصري@EgyHashX
    Active Exploitation

    الـ PoW هي مجرد خوارزمية إجماع، لا بتأثر على لا مركزية الشبكة ولا بتأثر على أمنها. البتكوين اللي بيستخدم الـ "PoW" تم اختراقه وسك 184 مليار عملة (CVE-2010-5139)، حصل عليه Double Spending، كان فيه ثغرات لإنشاء بتكوين جديد وكسر حاجز 21 مليون (CVE-2018-17144) كان فيه ثغرات كافية تقتل الشبكة (INVDoS) إلخ.

    Post summary

    The post alleges Bitcoin has been exploited, citing CVE‑2010‑5139 and CVE‑2018‑17144 as potential vector for double spending and network disruption, but offers no evidence or patch information.

    1012158.0K
    38.8K followersView on X
  • 윤회엔딩@EndTheKarma
    General

    비트코인에는 이전에 누군가가 "무한히 무료 비트코인을 발행"할 수 있는 두 가지 코드 취약점이 알려진 바 있습니다. CVE-2010-5139 버그는 2010년 8월 15일에 발표되었으며, 1840억 BTC의 비트코인을 발행했고, 비트코인 ​​체인 롤백을 필요로 했습니다. CVE-2018-17144 버그는 2018년 9월 17일에 발표되었으며, 비트코인캐시 개발자가 이를 발견하여 악용하는 대신 공개했습니다. 이건 새로운 수법이 아닙니다. 엉터리 반바지, 종이로 만든 은과 금, 제프리 엡스타인의 돈 찍어내는 기계, 일명 비트코인. 추신: 제프리 엡스타인이 비트코인 ​​재단에 투자했을 당시(알려진 바에 따르면 85만 달러) 비트코인 ​​가격은 겨우 225달러였습니다.

    Post summary

    The passage mentions two Bitcoin CVEs and notes their discovery dates and basic impact, but provides no PoC, exploit, active exploitation, or mitigation information.

    170182916
    3.5K followersView on X
  • N0x//@4nt1b110
    General

    @LukeDashjr You prob talking about CVE-2018-17144. The consensus spec never changed, overall intent never changed. The bug was never exploited so the actual chain was valid under both rulesets. There was absolute no chain divergence. You can’t stop lying, can you?

    Post summary

    The post indicates that CVE-2018-17144 was never exploited and offers no evidence of PoCs, exploits, patches, or technical details.

    2002411.4K
    35 followersView on X
  • Greg Tonoski, BIP-110@GregTonoski
    Disclosure

    @Sun_0f_A_Beach @mattkratter 💯 Matt Corallo had planted inflation bomb in Bitcoin Core in 2016 and when it was discovered the CVE-2018-17144 was recorded. Bitcoin Core™ issued the statement that Matt Corallo "identified [critical] inflation bug" (https://bitcoincore.org/en/2018/09/20/notice/).

    Post summary

    The tweet highlights that Matt Corallo discovered an inflation bug in Bitcoin Core, leading to the assignment of CVE‑2018‑17144, and references the official Bitcoin Core statement, but offers no PoC, exploit details, or mitigation information.

    020190217
    937 followersView on X
  • d7r@noD7R
    General

    There was also severe Bitcoin Core critical inflation bug in Sept 2018. Look for CVE-2018-17144.

    Post summary

    The post briefly references CVE‑2018‑17144 in Bitcoin Core but provides no additional information such as PoC, exploit details, exploitation reports, patches, or technical specifics.

    2111112.3K
    4.4K followersView on X
  • ambitious man .. طموح شاب@Ambitiousman0
    Active Exploitation

    المعلومة الثانية سبق أن تعرض البيتكوين لثغرتين خطيرتين: 1️⃣ CVE-2010-5139 سمحت بسكّ 184 مليار بيتكوين استدعت إعادة السلسلة 2️⃣ CVE-2018-17144 اكتشفها مطور من Bitcoin Cash وتم الإفصاح عنها بدل استغلالها ⚠️هاد الشخص او المنظمة كانوا حرفياً بيستغلوا كل شي ممكن يربح او يدخل اموال عليهم و عالناس من حولهم ...!!

    Post summary

    The post highlights two serious Bitcoin vulnerabilities, noting that CVE‑2010‑5139 was actively exploited to siphon billions of bitcoins, while CVE‑2018‑17144 was disclosed before exploitation.

    100150712
    22.3K followersView on X
  • Jeremiah@jeremiahrogers
    General

    Hey @saifedean! If CVE-2018-17144 had been exploited before Core maintainers coordinated with miners to push a fix: What coin would you support today? Let's say the exploit had printed a billion Bitcoin. Would you support the inflated Bitcoin or a rolled back chain? What if it happened today with a new bug?

    Post summary

    The tweet references CVE‑2018‑17144 in a hypothetical discussion, lacking concrete details about exploitation, patches, or technical specifics.

    000131757
    2.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbitcoinbitcoin_core---
Appbitcoinknotsbitcoin_knots---

Explore more