$BTC'S FIRST-EVER MEMORY BUG
Bitcoin developers disclosed CVE-2024-52911 on Tuesday, a high-severity bug in the network's main node software that let miners crash other people's nodes or potentially execute code on them remotely.
The use-after-free vulnerability in the script validation engine affected versions 0.14.1 through 28.4. Developer Niklas Gögge called it the first memory safety issue ever disclosed in the project's history.
Cory Fields of the MIT Digital Currency Initiative privately reported the bug in November 2024. Pieter Wuille shipped the fix in version 29.0 in April 2025, and the last vulnerable release line reached end of life last month. The exploit required burning hashpower on specially crafted invalid blocks, making it expensive in practice and likely never used.
Roughly 43% of Bitcoin nodes are still running pre-v29 software, per Clark Moody dashboard data.
Post summary
Bitcoin discloses a high‑severity use‑after‑free bug (CVE‑2024‑52911) that could allow code execution, but the exploit is impractical. A fix has been released in v29.0 and the vulnerable releases are now EOL.
A remote crash and potential remote code execution vulnerability has been disclosed by @bitcoincoreorg, affecting all versions before 29.0 and after 0.14.0:
https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/
The @eCash $XEC reference node implementation from @Bitcoin_ABC is not vulnerable to this bug.
The potential issue has been identified and a preventive patch committed in 2017 by @deadalnix, removing the risk of a use-after-free that is the root cause of this CVE: https://github.com/Bitcoin-ABC/bitcoin-abc/commit/f4f64ae534f255504b8e2286af1e11014b847dca
Post summary
CVE‑2024‑52911 is a remote crash/possible RCE vulnerability in Bitcoin Core disclosed by @bitcoincoreorg, with the risk already mitigated by a 2017 patch; the eCash node and Bitcoin ABC are unaffected.
NEW: Bitcoin Core patches CVE-2024-52911 — its first memory safety bug — before disclosing it this week.
The vulnerability, affecting versions 0.14.0 through 28.x, let miners remotely crash nodes with invalid blocks. Roughly 43% of active nodes were still vulnerable before 29.0.
Post summary
Bitcoin Core has released a patch for the memory safety bug CVE-2024-52911, highlighting affected versions and the proportion of active nodes remaining vulnerable.
LOL. Haters failed to hack BCH today by exploiting a Core bug that doesn't exist on BCH (https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/). They spent maybe ~$10k in hash to accomplish nothing. https://t.co/knz7u2dL8g
Post summary
The tweet reports a failed attempt to exploit CVE‑2024‑52911 on Bitcoin Cash, noting the bug does not exist on that chain, without providing PoC, exploit code, or evidence of active exploitation.
Bitcoin Core PoC crash for CVE-2024-52911.
ℹ️ Instructional lab testing, WIP, for a patched and disclosed vulnerability.
We're reproducing the failure mode behind a subtle C++ bug: early return + background checks + reverse destruction order → use-after-free.
Valuable case study given the codebase’s criticality and quality bar.
Post summary
The post highlights a proof‑of‑concept crash for CVE‑2024‑52911 in Bitcoin Core, detailing a subtle C++ use‑after‑free bug while noting the issue has been patched.
Bitcoin Core disclosed CVE-2024-52911.
This was not a cryptography failure. This was not a consensus-rule failure. This was a memory-lifetime failure in the parallel script validation engine.
Responsibly disclosed by Cory Fields (MIT DCI) with a PoC on November 2, 2024.
Official disclosure: https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/
Post summary
Bitcoin Core has publicly disclosed CVE‑2024‑52911, a memory‑lifetime flaw in its parallel script validation engine, and a PoC was released; no active exploitation or patch has been reported.
Bitcoin Core disclosed a high-severity memory safety bug on Tuesday.
It's the first of its kind in the project's history.
CVE-2024-52911 let miners crash and potentially execute remote code on victim nodes.
It was patched in v29, but some estimates say ~43% of nodes are still running vulnerable software.
Full story on @TheBlockCo
Post summary
Bitcoin Core disclosed CVE‑2024‑52911, a memory safety flaw that could allow remote code execution; it was fixed in v29, but a large portion of nodes still run vulnerable software.
‼️ UPGRADE YOUR BITCOIN NODE RIGHT NOW!
A high severity vulnerability was found and publicly disclosed
In this video I (try to) easily explain the bug and what's happening with the BTC network around the Script Interpreter Remote Crash (CVE-2024-52911)
+ 32% of all Bitcoin nodes are still running an unpatched version, per bitref-com data
+ this is a memory safety issue, related to C++
+ should Bitcoin be rewritten in Rust?
Article may be published soon with the explainer here on X and at both thecoding.substack (en) and codigoaberto.substack (pt-br)
Post summary
The post announces a high‑severity Bitcoin Core vulnerability (CVE‑2024‑52911), urges users to upgrade, and provides minimal technical detail about the exploit class.
Breaking News from yesterday
- 1inch liquidity provider Trusted Volumes exploited for $5.87M, same attacker behind March’s $5M 1inch Fusion V1 hack, now the 5th DeFi exploit this month
- Bitcoin Core disclosed first-ever memory safety bug (CVE-2024-52911), affecting versions 0.14.0–28.x; patched in v29.0 but ~43% of nodes still vulnerable
- Aave liquidated the Kelp DAO attacker’s remaining rsETH positions as the final step in recovering from the $292M April 28 exploit, with collateral sent to DeFi United’s Recovery Guardian multisig
- White House adviser Patrick Witt says the Digital Asset Market Clarity Act is targeting a pre-July 4 pass
- Morgan Stanley is rolling out crypto trading on E*Trade at 0.50% fees for all 8.6M clients, undercutting Coinbase, Robinhood, and Schwab
- 21Shares listed Strategy Yield ETN (STRC) on London Stock Exchange, first UK exchange-traded access to Strategy’s perpetual preferred stock
- MegaETH announced MOSS, a unified embedded wallet within MegaOS supporting real-world payments
- Coinbase launched gold and silver perp futures for non-US traders
- US and Iran nearing 14-point memorandum of understanding covering 12–15 year uranium enrichment moratorium, sanctions relief, and release of frozen funds
- GameStop CEO Ryan Cohen said eBay permanently suspended his account for posing a risk to the marketplace community
- GameStop CEO Ryan Cohen is auctioning personal collectibles on eBay, saying he’s selling stuff on eBay to pay for eBay
- Strategy says BTC appreciating just 2.3% annually is enough to fund all its dividends indefinitely
- NEAR Protocol is adding post-quantum cryptography, letting account holders rotate to quantum-safe keys in a single transaction
- Kraken launched CFTC-regulated spot margin trading for US retail with up to 10x leverage, first product on its newly acquired Bitnomial licenses
- Ondo, J.P. Morgan Kinexys, Mastercard, and Ripple completed first cross-border settlement of tokenized US Treasuries in near real time on XRP Ledger
- Centrifuge launched deSPXA on Base, tokenized S&P 500 exposure built with S&P Dow Jones Indices, managed by Janus Henderson
- Manta Network is sunsetting staking on May 20 citing token dilution, and taking full self-operated control of Manta Pacific’s L2 sequencer
- MetaMask and Pudgy Penguins launched a three-tier Soulbound Token series claimable until June 3, with the open edition available to any MetaMask wallet holder
- Coinbase submitted a formal comment letter to the OCC pushing back on proposed PPSI rules, arguing against de minimis requirements, arbitrary reserve thresholds, run-risk restrictions, and limits on white label or multi-issuance stablecoin models
- BNY, custodian of ~$59T in assets, is launching crypto custody in Abu Dhabi starting with BTC and ETH, later expanding to stablecoins and tokenized assets
Post summary
Bitcoin Core disclosed CVE-2024-52911, a memory‑safety bug patched in v29.0 while an active 1inch exploit continues to hit DeFi protocols, underscoring the need for timely patches.
#Bitcoin Core just reminded everyone of something uncomfortable. 👀
Even the strongest narratives in crypto still have trust assumptions hiding somewhere.
CVE-2024-52911 reportedly allowed miners, under specific conditions, to remotely execute code on Bitcoin full nodes through a memory safety flaw in Bitcoin Core.
The bug sat hidden for years.
The fix was merged quietly.
And a large part of the network reportedly remained vulnerable because node operators do not update automatically.
Now, before the maxi army starts barking:
This is not me saying “Bitcoin is dead.”
Relax. 😅
This is me saying the same thing I always say:
Trust Nothing. Verify Everything.
Because sovereignty is not only about the coin.
It is also about the software.
The implementation.
The maintainers.
The update process.
The diversity of clients.
The hidden assumptions most people never check.
If one dominant software implementation becomes the operational reality of a whole network, then a bug in that implementation can become systemic risk.
That does not destroy Bitcoin’s thesis.
But it should destroy the lazy idea that “decentralized” means “nothing can go wrong.”
Real decentralization is not just consensus.
It is resilience at every layer.
And that is exactly why tools like CipherIndex and the ZeroTrust mindset matter.
Not to attack chains.
To force better questions.
Who controls the code?
Who reviews the patch?
Who understands the risk?
Who updates the nodes?
What happens if one implementation fails?
Crypto does not need more blind believers.
It needs more people willing to verify before the market teaches them the hard way. 🟢
Post summary
The text discusses CVE‑2024‑52911, a memory‑safety flaw in Bitcoin Core that enabled remote code execution, noting that a patch was quietly merged yet many nodes remain vulnerable due to lack of automatic updates.
It's a high-severity bug (CVE-2024-52911): use-after-free in script validation that a miner could theoretically exploit with a crafted invalid block to crash nodes or (less likely) run code. Patched in v29.0 (April 2025), disclosed today. ~43% of nodes may still be on older versions—upgrade if you're running one. Expensive to exploit, no known real-world attacks.
Coin Bureau posts a mix of news, including risks and positives. Security issues like this matter for transparency in Bitcoin's infrastructure.
Post summary
The post announces CVE‑2024‑52911, a high‑severity use‑after‑free flaw in script validation, noting it is patchable in v29.0 and that no real‑world exploitation has been observed.
🚨 Bitcoin Core Fixes Critical Bug
Bitcoin Core quietly fixed CVE-2024-52911, a memory flaw affecting versions 0.14.0 to 28.x that still leaves outdated nodes exposed.
📰 Full Article:
https://crypto-economy.com/bitcoin-core-fixes-critical-memory-bug-in-secret-leaving-older-nodes-at-risk/
Post summary
Bitcoin Core released a patch for CVE-2024-52911, a memory flaw that impacted older node versions; no evidence of current exploitation or PoC is presented.
🚨 Bitcoin Core expone una vulnerabilidad crítica 🚨
Un fallo de alta severidad, CVE-2024-52911, permitió el cierre remoto de nodos.
El error afectó a versiones antiguas del software desde 0.14.0 hasta 28.x.
Cerca del 43% de los nodos podrían seguir expuestos.
Aunque la vulnerabilidad fue corregida, muchos operadores no actualizaron.
Es crucial mantener la infraestructura Bitcoin segura y actualizada.
Post summary
The text announces CVE-2024-52911, a high‑severity remote‑closure vulnerability in Bitcoin Core versions 0.14.0–28.x, notes that a patch has been released, but many operators remain unpatched.
The issue sits in parallel script validation.
Bitcoin Core builds a local vector<CScriptCheck> during block validation. Each CScriptCheck holds a non-owning pointer to PrecomputedTransactionData - the precomputed values needed for each input.
Official text (CVE-2024-52911): «Each CScriptCheck holds a pointer to a PrecomputedTransactionData object which stores some data needed by each input in the transaction.»
Post summary
The excerpt outlines the technical nature of CVE-2024-52911 in Bitcoin Core’s script validation mechanism but provides no evidence of exploitation, PoC, or remediation.
Bitcoin Core v29.0 fixes a high-severity use-after-free bug (CVE-2024-52911) that could allow attackers to remotely crash nodes. Upgrade your node today.
#Bitcoin#BitcoinCore#CyberSecurity#InfoSec#Blockchain#CryptoNews#CVE202452911#NodeOperator
https://securityonline.info/bitcoin-core-cve-2024-52911-use-after-free-node-crash-fix/ https://t.co/n3RWLPLKKH
Post summary
Bitcoin Core v29.0 includes a fix for CVE‑2024‑52911, a use‑after‑free flaw that could crash nodes; users should upgrade immediately.
An advisory has been released for CVE-2024-52911, flagging a high‑risk memory error in Bitcoin Core 0.14.0‑29.0 that can lead to remote crashes when validating specially crafted blocks.
Niklas Gögge (@dergoegge) posted to the Bitcoin-Dev mailing list disclosing CVE-2024-52911, a vulnerability affecting versions of Bitcoin Core after version 0.14.0 and before 29.0...
https://bitcoinops.org/en/newsletters/2026/05/15/#bitcoin-core-script-interpreter-remote-crash-disclosure
Post summary
The text announces the discovery of CVE-2024-52911, affecting Bitcoin Core versions 0.14.0 to before 29.0, without detailing exploitation, patches, or further technical specifics.
No, not a very bad thing for Bitcoin.
This use-after-free bug (CVE-2024-52911) was patched in v29.0 back in April 2025. It's expensive and complex for a miner to exploit, with no known real-world attacks. The network has stayed stable, and most nodes will catch up via upgrades. Bitcoin's design handles these transparently.
Post summary
CVE-2024-52911, a use‑after‑free bug in Bitcoin, was fixed in version 29.0 in April 2025 and has no reported real‑world exploitation.
📌 افشای باگ جدی در Bitcoin Core که امکان کرشکردن نودها توسط ماینرها را فراهم میکرد
توسعهدهندگان Bitcoin Core یک باگ با
شدت بالا را افشا کردند که میتوانست به ماینرها اجازه دهد برخی نودهای بیتکوین را از راه دور کرش کنند. این نقص با شناسه CVE-2024-52911 ثبت شده و نسخههای بعد از 0.14.0 و قبل از 29.0 را تحت تأثیر قرار میداد. مشکل در نسخه 29.0 که در آوریل 2025 منتشر شد برطرف شده است.
این باگ به نحوه پردازش اسکریپتها در مرحله اعتبارسنجی بلاک مربوط بود. یک بلاک دستکاریشده میتوانست باعث شود نود به دادهای دسترسی پیدا کند که قبلاً آزاد شده بود. این وضعیت در شرایطی رخ میداد که یک رشته پردازشی دادههای کششده را حذف میکرد، در حالی که رشتهای دیگر هنوز در حال استفاده از همان داده بود.
اجرای حمله ساده نبود، زیرا مهاجم باید بلاکی با اثبات کار معتبر تولید میکرد که در نهایت بهدلیل نامعتبر بودن، پاداشی دریافت نمیکرد. همین موضوع احتمال سوءاستفاده واقعی را بسیار کم کرده بود.
این نقص نخستینبار در نوامبر 2024 توسط Cory Fields گزارش شد. چهار روز بعد، Pieter Wuille یک اصلاح مخفیانه ارائه داد و این تغییر در دسامبر 2024 ادغام شد تا در نسخه 29.0 بهطور کامل رفع شود.
افشاگری طبق سیاست امنیتی Bitcoin Core و پس از پایان پشتیبانی نسخههای آسیبپذیر انجام شد. با این حال، نودهایی که هنوز از نسخههای قدیمیتر از 29.0 استفاده میکنند همچنان در معرض خطر هستند، زیرا Bitcoin Core بهصورت خودکار بهروزرسانی نمیشود و کاربران باید نسخه جدید را دستی نصب کنند.
گزارشهای گذشته نشان دادهاند که درصد قابلتوجهی از نودها معمولاً از نسخههای قدیمی استفاده میکنند، موضوعی که اهمیت بهروزرسانی منظم نرمافزار را برجسته میکند.
Post summary
CVE‑2024‑52911 is a high‑severity bug in Bitcoin Core that could let miners crash nodes via crafted blocks; the issue was disclosed with full technical details and fixed in version 29.0, with no evidence of active exploitation.
₿ Lord Kristaps Kaupe ($ is for sats)@kristapsk·
@Kruwed Which means you run Bitcoin Core 28 or older, which has CVE-2024-52911 script interpreter remote crash bug. https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/