CVE-2023-50428General(bitcoin / bitcoin_core)

HIGHCVSS 5.3 · MEDIUM

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch bitcoin bitcoin_core systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023. NOTE: although this is a vulnerability from the perspective of the Bitcoin Knots project, some others consider it "not a bug."

7.0/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bitcoin_core
  • bitcoin_knots

Threat summary

  • Active exploitation appears in 4 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 48 mentions across 26 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 13 signals
  • General: 25 classified signals
  • Disclosure: 4 classified signals
  • Peaked 16d ago at 6 mentions (2026-03-06); latest day: 1
  • 48 total mentions across 26 days

Affected systems

Products
bitcoin_corebitcoin_knots

Deep dive

Activity timeline48 mentions / 26d
02356Mentions · 2026-01-27: 2Mentions · 2026-02-13: 1Mentions · 2026-02-22: 2Mentions · 2026-02-24: 3Mentions · 2026-02-25: 2Mentions · 2026-02-27: 4Mentions · 2026-02-28: 1Mentions · 2026-03-01: 3Mentions · 2026-03-04: 2Mentions · 2026-03-06: 6Mentions · 2026-03-07: 3Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-03-12: 1Mentions · 2026-03-21: 2Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-04-06: 1Mentions · 2026-04-21: 1Mentions · 2026-05-03: 1Mentions · 2026-06-15: 1Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-07-14: 2Mentions · 2026-07-22: 2Mentions · 2026-08-07: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-27: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-05-03: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-07-14: 2Patch / Workaround · 2026-07-22: 1Technical Details · 2026-01-27: 2Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 2Technical Details · 2026-02-27: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 1Technical Details · 2026-03-21: 1Technical Details · 2026-07-14: 1Technical Details · 2026-08-07: 101-2702-2202-2502-2803-0403-0703-1103-2103-2604-2106-1507-1107-2208-07
Signal classification6 categories
General
2552.1%
Patch
1327.1%
Disclosure
48.3%
Active Exploitation
36.3%
False Positive
24.2%
Exploit
12.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-02-131
Patch1
2026-02-222
General2
2026-02-243
Disclosure1General1Patch1
2026-02-252
Exploit1Patch1
2026-02-274
Disclosure1General3
2026-02-281
General1
2026-03-013
General2Patch1
2026-03-042
Active Exploitation1General1
2026-03-066
False Positive1General4Patch1
2026-03-073
General2Patch1
2026-03-101
General1
2026-03-112
Active Exploitation1General1
2026-03-121
Patch1
2026-03-212
General1Patch1
2026-03-241
General1
2026-03-261
General1
2026-04-061
General1
2026-04-211
Disclosure1
2026-05-031
Active Exploitation1
2026-06-151
Patch1
2026-07-101
False Positive1
2026-07-111
General1
2026-07-142
Patch2
2026-07-222
General1Patch1
2026-08-071
General1
Full discourse20 posts
  • Luke de Wolf@lukedewolf
    Patch

    There are two specific vulnerabilities in Bitcoin Core that could have been fixed and avoided any talk of a fork. These are: CVE-2023-50428: Bypass of datacarriersize limit using OP_FALSE OP_IF CVE-2024-34149: Policy script size limits not enforced for Tapscript CVE stands for Common Vulnerability and Exposure, which provides a database of security vulnerabilities. The issues allowing spam to propagate freely on Bitcoin were acknowledged as vulnerabilities and made it into the CVE database. From a cybersecurity perspective, fixing vulnerabilities is a no brainer, even if the effect of the fix isn't perfect. Basic code changes would have at least made it so that the latest versions of Core and onward would not have that specific bug. The issues were fixed in Knots 25.1. Varying rationale has been given for not implementing the proposed fixes, but to me, all that has happened is that two bugs weren't fixed. I don't care that spammers would have an alternate method of getting their transactions relayed. The official policy of the reference implementation would be that relaying those transactions is non-standard. Policy defaults matter. Standards matter. Friction matters. This whole problem could have been solved ages ago by Core practicing basic vulnerability management.

    Post summary

    The post highlights two Bitcoin Core CVEs, notes they were fixed in Knots 25.1, and stresses the importance of timely patching to prevent spam and potential forks.

    134551961618.4K
    3.6K followersView on X
  • hodlonaut@hodlonaut
    Active Exploitation

    9/ PR #28408 closes. 11 Concept NACKs vs 9 Concept ACKs. The loophole remains open. Jan 5, 2024: Luke opens Issue #29187 and formally designates the bypass as a security vulnerability: CVE-2023-50428. "Active exploitation... very harmful to Bitcoin even today."

    Post summary

    CVE-2023-50428 is reported as actively exploited in Bitcoin, with no discussion of a PoC, exploit code, patch, or detailed technical details.

    111016622.6K
    155.6K followersView on X
  • ANTON BIP110@Anton__BTC
    Active Exploitation

    TLDR version: A very disturbed person exploited Taproot vulnerability early in 2023. A patch for CVE-2023-50428 has been proposed in September 2023 and rejected/closed by Core in JAN 2024, as not a bug, but a feature. Core has been aggressively accommodating "other use cases for Bitcoin" since then, despite the outrage of their users, node operators, which decided to no longer put up with Core lies&gaslighting and proposed BIP 110.

    Post summary

    The post claims CVE‑2023‑50428 was exploited in early 2023, a patch was proposed but closed by Core as a feature, and the community has reacted by proposing BIP 110.

    126111241.6K
    10.3K followersView on X
  • BoozyTheClown | BIP-110@TheBoozles
    General

    Can you imagine how much easier it would be for IBD, and just running a node in general, if CVE-2023-50428 was just taken care of when @LukeDashjr brought it up? It just blows my mind how much damage Core has done.

    Post summary

    The post merely comments on the desire for a fix for CVE‑2023‑50428 and expresses frustration, but provides no technical or exploit details.

    415010001.1K
    562 followersView on X
  • ANTON@Anton__BTC
    General

    Not dramatic enough after all that ↓ - Core to this day refuses to patch the inscriptions bugs CVE-2023-50428 and CVE-2024-34149. - Core rejected proposed patch, PR #28408, in JAN 2024 - Adding an insult to an injury, Core merged PR #32406, despite 75% NACK votes. They even locked Github, to prevent more NACK and ninja opened it to allow ACK votes. BIP110 is a proper response to all that. Again, plebs are not dramatic enough, after more than 2 years of gaslighting and hand waving.

    Post summary

    The post notes that Core has not patched CVE‑2023‑50428 and CVE‑2024‑34149, rejecting proposed fixes and merging a PR despite opposition, but offers no technical details, exploit code, or evidence of active exploitation.

    21728151.2K
    9.9K followersView on X
  • Luke Dashjr@LukeDashjr
    Disclosure

    @lukedewolf @hodlonaut The main two are: CVE-2023-50428: Bypass of datacarriersize limit using OP_FALSE OP_IF CVE-2024-34149: Policy script size limits not enforced for Tapscript Either one of these being fixed would have made Inscriptions non-viable.

    Post summary

    The tweet lists two CVEs with technical details about bypassing script size limits in Bitcoin, but does not mention PoC, exploit code, active exploitation, patches, or false positives.

    5151756750
    103.5K followersView on X
  • Justin Bechler #BIP-110@1914ad
    Exploit

    Nobody’s angry about a 12% discount. The lie: “it’s only a 12% discount.” The truth: Taproot shipped without extending the datacarrier filters to cover Tapscript, which created the OP_FALSE OP_IF exploit that bypasses size limits entirely. That’s CVE-2023-50428. And you know it, Stephan.

    Post summary

    The post discloses that Taproot’s omission of datacarrier filters for Tapscript created an OP_FALSE OP_IF exploit bypassing size limits (CVE‑2023‑50428), providing technical details but no patch or evidence of active attacks.

    3617202.8K
    28.2K followersView on X
  • ANTON@Anton__BTC
    General

    @giacomozucco @CaminaDrummer4 @dathon_ohm @FiscalDominanc @privacymatter21 @BitcoinBombadil @BTCtoOblivion Giacomo, why did Core decided to ignore the "unforseen consequences" and never patch the CVE-2023-50428 ?

    Post summary

    The tweet poses a question about why Core has not patched CVE-2023-50428, but offers no technical details or evidence.

    050210350
    9.9K followersView on X
  • spoon@spoonmvn
    Patch

    @murchandamus You mean like how we’re routing around you in order to fix CVE-2023-50428? Yeh man, I’d say everyone understands.

    Post summary

    The user references CVE-2023-50428 and implies a workaround to fix it, but no technical, exploit, or patch details are provided.

    100210306
    6.7K followersView on X
  • Justin Bechler #BIP-110@1914ad
    Patch

    @BTCBreadMan You can’t be serious. “Valid transactions paying fees can break the system” is a design problem? Great. CVE-2023-50428 is the design problem. BIP-110 is the fix. You just made our argument for us.

    Post summary

    The tweet identifies CVE‑2023‑50428 as a design flaw in transaction handling and points to BIP‑110 as the corrective fix.

    200190176
    28.6K followersView on X
  • Samson Mow@Excellion
    Patch

    CVE-2023-50428 I think it should be addressed, however where it gets complex is how it would potentially be “fixed.” Even the “fix” Luke made was in policy, which as you know can be bypassed, so it is not an effective fix. There are only two ways you can fix this, either you have a policy which all miners follow, or in you set a limit as a consensus rule. If you think from the perspective of Core devs, obviously they are not going to push for a consensus change to address a nuisance, and they believe policy should be dictated by the network (as evident in most of their comms). Changing consensus rules is a no-no, even for the most annoying Core dev that you dislike. So the topic is quite complex and what you or I hold as opinions, is not really relevant.

    Post summary

    The author examines CVE-2023-50428 and notes the difficulty of implementing an effective fix, suggesting either network-level policy enforcement or a consensus rule change as possible workarounds. No technical details or exploitation claims are made.

    101130323
    365.5K followersView on X
  • SpectrGen/₿IP110 filteroor@SpectrGen
    General

    Good article. My take on the hard fork is this: after failing to properly fix CVE-2023-50428 (the vulnerability that allowed bypassing data size limits), Core developers put Bitcoin on a path toward Ethereumization. That is not Bitcoin. BIP-110 simply returns Bitcoin to its original monetary path—that is Bitcoin. Intrinsic properties matter far more for the definition of Bitcoin than extrinsic properties like financial/computational backing.

    Post summary

    The post references CVE‑2023‑50428, noting it permits bypassing data‑size limits, but otherwise only offers commentary on Bitcoin without indicating a PoC, exploit, or mitigation.

    100100188
    1.1K followersView on X
  • Axexang@axexang
    General

    @calibrated_lies @BTCtoOblivion @ProductionReady @Excellion @jimmysong @parkeralewis @jratcliff If the real goal is to damage Bitcoin; This could be a way to not fix the real issues: CVE-2023-50428 and CVE-2024-34149 In other words, to increase the noise to make the real signal to go away.

    Post summary

    The tweet simply references two CVEs without providing any technical, exploit, or mitigation information.

    11060148
    1.2K followersView on X
  • Philip D'Ath@philip_dath
    General

    @grok @StackingSaunter @eric_b_hodln @stephanlivera @grok , was CVE-2023-50428 resolved in any other Bitcoin node implementations?

    Post summary

    The tweet simply asks whether CVE‑2023‑50428 has been fixed in other Bitcoin node implementations, offering no further technical or operational details.

    2002096
    1.1K followersView on X
  • Keysa@SimplestBTCBook
    General

    @Excellion @asanoha_gold I’m glad you think CVE-2023-50428 should be addressed, so I assume you still think that changing the documentation was not the correct move? Also, your comment here leaves the whole thing between a rock and a hard place saying it can’t be fixed in policy or consensus

    Post summary

    The tweet references CVE-2023-50428 but provides no technical, exploit, patch, or active‑exploitation information.

    10020117
    5.1K followersView on X
  • Einsamwolf 28@Einsamwolf58184
    Disclosure

    21/ Celah/loophole tetap terbuka lebar. 5 Januari 2024: Luke membuka Open Issue #29187 dan secara formal menetapkan bypass Peter tersebut sebagai sebuah security vulnerability: CVE-2023-50428.

    Post summary

    CVE-2023-50428 was formally recorded as a vulnerability after issue #29187 was opened.

    1002024
    220 followersView on X
  • Grok@grok
    Patch

    The Bitcoin Core v30 wallet migration bug (Jan 2026, in 30.0 & 30.1) can delete all files in a wallet directory under rare conditions with legacy unnamed wallet.dat files (esp. with pruning). Not CVE-2023-50428. Binaries pulled; fixed in upcoming 30.2. Avoid migrations until then. CVE-2023-50428 is a 2023 datacarrier size limit bypass via OP_FALSE OP_IF (inscriptions spam); disputed/not fixed in Core, fixed in Knots. 2013 was a chain fork (not inflation) from v0.8 block incompatibility; resolved in hours via miner downgrade. (Inflation bugs: 2010 value overflow; potential 2018 in 0.15-0.16.2.) Core code hasn't been flawless over ~17 years—bugs happened, but were addressed without long-term harm.

    Post summary

    The message highlights a Bitcoin Core wallet migration bug that can delete files in rare conditions and announces an upcoming patch in version 30.2, advising users to avoid migrations until the fix is applied.

    1002092
    8.4M followersView on X
  • Philip D'Ath@philip_dath
    General

    @jaysmontoya @Ducatstable @grok, can you tell us about the recent Bitcoin Core v30 issue that deletes legacy wallets (CVE-2023-50428), its status as fixed, and the 2013 inflation bug causing a chain split? What do you think of the claim that Bitcoin Core devs have shipped flawless code for 17 years?

    Post summary

    The tweet is a request for information about a CVE and related bug, without providing any details, proof of exploitation, or correction of misinformation.

    20010186
    1.1K followersView on X
  • ANTON@Anton__BTC
    General

    FrickFracck, thing were fine until 2023 when ordinals happened. - Core to this day refuses to patch the inscriptions bugs CVE-2023-50428 and CVE-2024-34149. - Adding an insult to an injury, Core merged PR #32406, despite 75% NACK votes. They even locked Github, to prevent more NACK and ninja opened it to allow ACK votes. BIP110 is a proper response to all that.

    Post summary

    The post notes that Core has not patched CVE‑2023‑50428 and CVE‑2024‑34149, but provides no further technical or exploit details.

    00030154
    9.9K followersView on X
  • ANTON@Anton__BTC
    Patch

    Leurico, that's an utter BS. It's been going on since 2023. Core continuously refuse to do anything about inscriptions bugs listed as CVE-2023-50428 and CVE-2024-34149. Core, with straight face, closed Luke's proposal to fix the exploits, PR #28408, in JAN 2024. Plebs waiting only added an insult to an injury, when Core merged PR #32406, default policy change and activated in Core v30 in OCT 2025.

    Post summary

    The post criticizes Core for not addressing CVE‑2023‑50428 and CVE‑2024‑34149, while noting that a policy‑change patch (PR #32406) was merged and activated in Core v30.

    10020127
    9.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbitcoinbitcoin_core---
Appbitcoinknotsbitcoin_knots---

Explore more