CVE-2024-52911Patch

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 25 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14.

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 70 mentions across 17 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 44 signals
  • Technical details provided in 49 signals
  • Disclosure: 25 classified signals
  • General: 10 classified signals
  • Peaked 15d ago at 25 mentions (2026-05-06); latest day: 1
  • 70 total mentions across 17 days

Deep dive

Activity timeline70 mentions / 17d
06131925Mentions · 2026-05-05: 6Mentions · 2026-05-06: 25Mentions · 2026-05-07: 11Mentions · 2026-05-08: 8Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 5Mentions · 2026-05-16: 2Mentions · 2026-05-25: 3Mentions · 2026-05-27: 1Mentions · 2026-07-28: 1Mentions · 2026-07-31: 1Mentions · 2026-08-07: 1Mentions · 2026-08-19: 1Mentions · 2026-08-28: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-15: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-08-28: 1Patch / Workaround · 2026-05-05: 3Patch / Workaround · 2026-05-06: 15Patch / Workaround · 2026-05-07: 8Patch / Workaround · 2026-05-08: 5Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-16: 1Patch / Workaround · 2026-05-25: 3Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-07-28: 1Patch / Workaround · 2026-07-31: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-05-05: 4Technical Details · 2026-05-06: 19Technical Details · 2026-05-07: 9Technical Details · 2026-05-08: 7Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-16: 2Technical Details · 2026-05-25: 2Technical Details · 2026-07-31: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-28: 105-0505-0605-0705-0805-1105-1205-1405-1505-1605-2505-2707-2807-3108-0708-1908-2809-30
Signal classification4 categories
Patch
3347.8%
Disclosure
2536.2%
General
1014.5%
PoC
11.4%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-056
Disclosure3General2Patch1
2026-05-0625
Disclosure12Patch13
2026-05-0711
Disclosure4Patch7
2026-05-088
Disclosure1General2Patch5
2026-05-111
Disclosure1
2026-05-121
Patch1
2026-05-141
Disclosure1
2026-05-155
Disclosure1General3PoC1
2026-05-162
General1Patch1
2026-05-253
General1Patch2
2026-05-271
Patch1
2026-07-281
Patch1
2026-07-311
General1
2026-08-071
Patch1
2026-08-191
Disclosure1
2026-08-281
Disclosure1
Full discourse20 posts
  • BSCN@BSCNews
    Patch

    $BTC'S FIRST-EVER MEMORY BUG Bitcoin developers disclosed CVE-2024-52911 on Tuesday, a high-severity bug in the network's main node software that let miners crash other people's nodes or potentially execute code on them remotely. The use-after-free vulnerability in the script validation engine affected versions 0.14.1 through 28.4. Developer Niklas Gögge called it the first memory safety issue ever disclosed in the project's history. Cory Fields of the MIT Digital Currency Initiative privately reported the bug in November 2024. Pieter Wuille shipped the fix in version 29.0 in April 2025, and the last vulnerable release line reached end of life last month. The exploit required burning hashpower on specially crafted invalid blocks, making it expensive in practice and likely never used. Roughly 43% of Bitcoin nodes are still running pre-v29 software, per Clark Moody dashboard data.

    Post summary

    Bitcoin discloses a high‑severity use‑after‑free bug (CVE‑2024‑52911) that could allow code execution, but the exploit is impractical. A fix has been released in v29.0 and the vulnerable releases are now EOL.

    103231343728.8K
    1.4M followersView on X
  • eCash@eCash
    Disclosure

    A remote crash and potential remote code execution vulnerability has been disclosed by @bitcoincoreorg, affecting all versions before 29.0 and after 0.14.0: https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/ The @eCash $XEC reference node implementation from @Bitcoin_ABC is not vulnerable to this bug. The potential issue has been identified and a preventive patch committed in 2017 by @deadalnix, removing the risk of a use-after-free that is the root cause of this CVE: https://github.com/Bitcoin-ABC/bitcoin-abc/commit/f4f64ae534f255504b8e2286af1e11014b847dca

    Post summary

    CVE‑2024‑52911 is a remote crash/possible RCE vulnerability in Bitcoin Core disclosed by @bitcoincoreorg, with the risk already mitigated by a 2017 patch; the eCash node and Bitcoin ABC are unaffected.

    331510427.8K
    111.5K followersView on X
  • Bitcoin News@BitcoinNewsCom
    Patch

    NEW: Bitcoin Core patches CVE-2024-52911 — its first memory safety bug — before disclosing it this week. The vulnerability, affecting versions 0.14.0 through 28.x, let miners remotely crash nodes with invalid blocks. Roughly 43% of active nodes were still vulnerable before 29.0.

    Post summary

    Bitcoin Core has released a patch for the memory safety bug CVE-2024-52911, highlighting affected versions and the proportion of active nodes remaining vulnerable.

    3733755.8K
    262.7K followersView on X
  • Calin Culianu@cculianu
    General

    LOL. Haters failed to hack BCH today by exploiting a Core bug that doesn't exist on BCH (https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/). They spent maybe ~$10k in hash to accomplish nothing. https://t.co/knz7u2dL8g

    Post summary

    The tweet reports a failed attempt to exploit CVE‑2024‑52911 on Bitcoin Cash, noting the bug does not exist on that chain, without providing PoC, exploit code, or evidence of active exploitation.

    082320642
    1.9K followersView on X
  • Coinspect Security@coinspect
    PoC

    Bitcoin Core PoC crash for CVE-2024-52911. ℹ️ Instructional lab testing, WIP, for a patched and disclosed vulnerability. We're reproducing the failure mode behind a subtle C++ bug: early return + background checks + reverse destruction order → use-after-free. Valuable case study given the codebase’s criticality and quality bar.

    Post summary

    The post highlights a proof‑of‑concept crash for CVE‑2024‑52911 in Bitcoin Core, detailing a subtle C++ use‑after‑free bug while noting the issue has been patched.

    0601661.9K
    3.0K followersView on X
  • Matt EX@M477EX
    Disclosure

    Bitcoin Core disclosed CVE-2024-52911. This was not a cryptography failure. This was not a consensus-rule failure. This was a memory-lifetime failure in the parallel script validation engine. Responsibly disclosed by Cory Fields (MIT DCI) with a PoC on November 2, 2024. Official disclosure: https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/

    Post summary

    Bitcoin Core has publicly disclosed CVE‑2024‑52911, a memory‑lifetime flaw in its parallel script validation engine, and a PoC was released; no active exploitation or patch has been reported.

    320143374
    63 followersView on X
  • Naga Avan-Nomayo@JeSuisNaga
    Patch

    Bitcoin Core disclosed a high-severity memory safety bug on Tuesday. It's the first of its kind in the project's history. CVE-2024-52911 let miners crash and potentially execute remote code on victim nodes. It was patched in v29, but some estimates say ~43% of nodes are still running vulnerable software. Full story on @TheBlockCo

    Post summary

    Bitcoin Core disclosed CVE‑2024‑52911, a memory safety flaw that could allow remote code execution; it was fixed in v29, but a large portion of nodes still run vulnerable software.

    3301324.4K
    4.0K followersView on X
  • Vini B |「 thecoding 」@vinibarbosabr
    Disclosure

    ‼️ UPGRADE YOUR BITCOIN NODE RIGHT NOW! A high severity vulnerability was found and publicly disclosed In this video I (try to) easily explain the bug and what's happening with the BTC network around the Script Interpreter Remote Crash (CVE-2024-52911) + 32% of all Bitcoin nodes are still running an unpatched version, per bitref-com data + this is a memory safety issue, related to C++ + should Bitcoin be rewritten in Rust? Article may be published soon with the explainer here on X and at both thecoding.substack (en) and codigoaberto.substack (pt-br)

    Post summary

    The post announces a high‑severity Bitcoin Core vulnerability (CVE‑2024‑52911), urges users to upgrade, and provides minimal technical detail about the exploit class.

    2311101.5K
    11.8K followersView on X
  • 🐍Salazar.eth 🦇🔊@0xSalazar
    Patch

    Breaking News from yesterday - 1inch liquidity provider Trusted Volumes exploited for $5.87M, same attacker behind March’s $5M 1inch Fusion V1 hack, now the 5th DeFi exploit this month - Bitcoin Core disclosed first-ever memory safety bug (CVE-2024-52911), affecting versions 0.14.0–28.x; patched in v29.0 but ~43% of nodes still vulnerable - Aave liquidated the Kelp DAO attacker’s remaining rsETH positions as the final step in recovering from the $292M April 28 exploit, with collateral sent to DeFi United’s Recovery Guardian multisig​​​​​​​​​​​​​​​​ - White House adviser Patrick Witt says the Digital Asset Market Clarity Act is targeting a pre-July 4 pass - Morgan Stanley is rolling out crypto trading on E*Trade at 0.50% fees for all 8.6M clients, undercutting Coinbase, Robinhood, and Schwab - 21Shares listed Strategy Yield ETN (STRC) on London Stock Exchange, first UK exchange-traded access to Strategy’s perpetual preferred stock - MegaETH announced MOSS, a unified embedded wallet within MegaOS supporting real-world payments - Coinbase launched gold and silver perp futures for non-US traders - US and Iran nearing 14-point memorandum of understanding covering 12–15 year uranium enrichment moratorium, sanctions relief, and release of frozen funds - GameStop CEO Ryan Cohen said eBay permanently suspended his account for posing a risk to the marketplace community​​​​​​​​​​​​​​​​ - GameStop CEO Ryan Cohen is auctioning personal collectibles on eBay, saying he’s selling stuff on eBay to pay for eBay​​​​​​​​​​​​​​​​ - Strategy says BTC appreciating just 2.3% annually is enough to fund all its dividends indefinitely - NEAR Protocol is adding post-quantum cryptography, letting account holders rotate to quantum-safe keys in a single transaction - Kraken launched CFTC-regulated spot margin trading for US retail with up to 10x leverage, first product on its newly acquired Bitnomial licenses - Ondo, J.P. Morgan Kinexys, Mastercard, and Ripple completed first cross-border settlement of tokenized US Treasuries in near real time on XRP Ledger - Centrifuge launched deSPXA on Base, tokenized S&P 500 exposure built with S&P Dow Jones Indices, managed by Janus Henderson - Manta Network is sunsetting staking on May 20 citing token dilution, and taking full self-operated control of Manta Pacific’s L2 sequencer - MetaMask and Pudgy Penguins launched a three-tier Soulbound Token series claimable until June 3, with the open edition available to any MetaMask wallet holder - Coinbase submitted a formal comment letter to the OCC pushing back on proposed PPSI rules, arguing against de minimis requirements, arbitrary reserve thresholds, run-risk restrictions, and limits on white label or multi-issuance stablecoin models - BNY, custodian of ~$59T in assets, is launching crypto custody in Abu Dhabi starting with BTC and ETH, later expanding to stablecoins and tokenized assets

    Post summary

    Bitcoin Core disclosed CVE-2024-52911, a memory‑safety bug patched in v29.0 while an active 1inch exploit continues to hit DeFi protocols, underscoring the need for timely patches.

    310100932
    66.5K followersView on X
  • ØxGshep@OxGshep
    Patch

    #Bitcoin Core just reminded everyone of something uncomfortable. 👀 Even the strongest narratives in crypto still have trust assumptions hiding somewhere. CVE-2024-52911 reportedly allowed miners, under specific conditions, to remotely execute code on Bitcoin full nodes through a memory safety flaw in Bitcoin Core. The bug sat hidden for years. The fix was merged quietly. And a large part of the network reportedly remained vulnerable because node operators do not update automatically. Now, before the maxi army starts barking: This is not me saying “Bitcoin is dead.” Relax. 😅 This is me saying the same thing I always say: Trust Nothing. Verify Everything. Because sovereignty is not only about the coin. It is also about the software. The implementation. The maintainers. The update process. The diversity of clients. The hidden assumptions most people never check. If one dominant software implementation becomes the operational reality of a whole network, then a bug in that implementation can become systemic risk. That does not destroy Bitcoin’s thesis. But it should destroy the lazy idea that “decentralized” means “nothing can go wrong.” Real decentralization is not just consensus. It is resilience at every layer. And that is exactly why tools like CipherIndex and the ZeroTrust mindset matter. Not to attack chains. To force better questions. Who controls the code? Who reviews the patch? Who understands the risk? Who updates the nodes? What happens if one implementation fails? Crypto does not need more blind believers. It needs more people willing to verify before the market teaches them the hard way. 🟢

    Post summary

    The text discusses CVE‑2024‑52911, a memory‑safety flaw in Bitcoin Core that enabled remote code execution, noting that a patch was quietly merged yet many nodes remain vulnerable due to lack of automatic updates.

    010130243
    1.9K followersView on X
  • Grok@grok
    Disclosure

    It's a high-severity bug (CVE-2024-52911): use-after-free in script validation that a miner could theoretically exploit with a crafted invalid block to crash nodes or (less likely) run code. Patched in v29.0 (April 2025), disclosed today. ~43% of nodes may still be on older versions—upgrade if you're running one. Expensive to exploit, no known real-world attacks. Coin Bureau posts a mix of news, including risks and positives. Security issues like this matter for transparency in Bitcoin's infrastructure.

    Post summary

    The post announces CVE‑2024‑52911, a high‑severity use‑after‑free flaw in script validation, noting it is patchable in v29.0 and that no real‑world exploitation has been observed.

    210100487
    8.7M followersView on X
  • Crypto Economy News@CryptoEconomyEN
    Patch

    🚨 Bitcoin Core Fixes Critical Bug Bitcoin Core quietly fixed CVE-2024-52911, a memory flaw affecting versions 0.14.0 to 28.x that still leaves outdated nodes exposed. 📰 Full Article: https://crypto-economy.com/bitcoin-core-fixes-critical-memory-bug-in-secret-leaving-older-nodes-at-risk/

    Post summary

    Bitcoin Core released a patch for CVE-2024-52911, a memory flaw that impacted older node versions; no evidence of current exploitation or PoC is presented.

    12080904
    6.4K followersView on X
  • Diario฿itcoin@DiarioBitcoin
    Disclosure

    🚨 Bitcoin Core expone una vulnerabilidad crítica 🚨 Un fallo de alta severidad, CVE-2024-52911, permitió el cierre remoto de nodos. El error afectó a versiones antiguas del software desde 0.14.0 hasta 28.x. Cerca del 43% de los nodos podrían seguir expuestos. Aunque la vulnerabilidad fue corregida, muchos operadores no actualizaron. Es crucial mantener la infraestructura Bitcoin segura y actualizada.

    Post summary

    The text announces CVE-2024-52911, a high‑severity remote‑closure vulnerability in Bitcoin Core versions 0.14.0–28.x, notes that a patch has been released, but many operators remain unpatched.

    32131380
    210.8K followersView on X
  • Matt EX@M477EX
    General

    The issue sits in parallel script validation. Bitcoin Core builds a local vector<CScriptCheck> during block validation. Each CScriptCheck holds a non-owning pointer to PrecomputedTransactionData - the precomputed values needed for each input. Official text (CVE-2024-52911): «Each CScriptCheck holds a pointer to a PrecomputedTransactionData object which stores some data needed by each input in the transaction.»

    Post summary

    The excerpt outlines the technical nature of CVE-2024-52911 in Bitcoin Core’s script validation mechanism but provides no evidence of exploitation, PoC, or remediation.

    10080173
    63 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Bitcoin Core v29.0 fixes a high-severity use-after-free bug (CVE-2024-52911) that could allow attackers to remotely crash nodes. Upgrade your node today. #Bitcoin #BitcoinCore #CyberSecurity #InfoSec #Blockchain #CryptoNews #CVE202452911 #NodeOperator https://securityonline.info/bitcoin-core-cve-2024-52911-use-after-free-node-crash-fix/ https://t.co/n3RWLPLKKH

    Post summary

    Bitcoin Core v29.0 includes a fix for CVE‑2024‑52911, a use‑after‑free flaw that could crash nodes; users should upgrade immediately.

    02051480
    12.5K followersView on X
  • 吴说区块链@wublockchain12
    Disclosure

    吴说获悉,比特币核心开发团队 Bitcoin Core Project 发布高危安全通告(CVE-2024-52911),称在 Bitcoin Core 0.14.0 至 29.0 版本之间,节点在验证特制区块时可能触发内存错误,导致远程崩溃。

    Post summary

    An advisory has been released for CVE-2024-52911, flagging a high‑risk memory error in Bitcoin Core 0.14.0‑29.0 that can lead to remote crashes when validating specially crafted blocks.

    400316.6K
    178.3K followersView on X
  • Bitcoin Optech@bitcoinoptech
    General

    Niklas Gögge (@dergoegge) posted to the Bitcoin-Dev mailing list disclosing CVE-2024-52911, a vulnerability affecting versions of Bitcoin Core after version 0.14.0 and before 29.0... https://bitcoinops.org/en/newsletters/2026/05/15/#bitcoin-core-script-interpreter-remote-crash-disclosure

    Post summary

    The text announces the discovery of CVE-2024-52911, affecting Bitcoin Core versions 0.14.0 to before 29.0, without detailing exploitation, patches, or further technical specifics.

    12040388
    18.4K followersView on X
  • Grok@grok
    Patch

    No, not a very bad thing for Bitcoin. This use-after-free bug (CVE-2024-52911) was patched in v29.0 back in April 2025. It's expensive and complex for a miner to exploit, with no known real-world attacks. The network has stayed stable, and most nodes will catch up via upgrades. Bitcoin's design handles these transparently.

    Post summary

    CVE-2024-52911, a use‑after‑free bug in Bitcoin, was fixed in version 29.0 in April 2025 and has no reported real‑world exploitation.

    00060165
    8.7M followersView on X
  • Ourbit Farsi@Ourbit_Farsi
    Disclosure

    📌 افشای باگ جدی در Bitcoin Core که امکان کرش‌کردن نودها توسط ماینرها را فراهم می‌کرد توسعه‌دهندگان Bitcoin Core یک باگ با شدت بالا را افشا کردند که می‌توانست به ماینرها اجازه دهد برخی نودهای بیت‌کوین را از راه دور کرش کنند. این نقص با شناسه CVE-2024-52911 ثبت شده و نسخه‌های بعد از 0.14.0 و قبل از 29.0 را تحت تأثیر قرار می‌داد. مشکل در نسخه 29.0 که در آوریل 2025 منتشر شد برطرف شده است. این باگ به نحوه پردازش اسکریپت‌ها در مرحله اعتبارسنجی بلاک مربوط بود. یک بلاک دست‌کاری‌شده می‌توانست باعث شود نود به داده‌ای دسترسی پیدا کند که قبلاً آزاد شده بود. این وضعیت در شرایطی رخ می‌داد که یک رشته پردازشی داده‌های کش‌شده را حذف می‌کرد، در حالی که رشته‌ای دیگر هنوز در حال استفاده از همان داده بود. اجرای حمله ساده نبود، زیرا مهاجم باید بلاکی با اثبات کار معتبر تولید می‌کرد که در نهایت به‌دلیل نامعتبر بودن، پاداشی دریافت نمی‌کرد. همین موضوع احتمال سوءاستفاده واقعی را بسیار کم کرده بود. این نقص نخستین‌بار در نوامبر 2024 توسط Cory Fields گزارش شد. چهار روز بعد، Pieter Wuille یک اصلاح مخفیانه ارائه داد و این تغییر در دسامبر 2024 ادغام شد تا در نسخه 29.0 به‌طور کامل رفع شود. افشاگری طبق سیاست امنیتی Bitcoin Core و پس از پایان پشتیبانی نسخه‌های آسیب‌پذیر انجام شد. با این حال، نودهایی که هنوز از نسخه‌های قدیمی‌تر از 29.0 استفاده می‌کنند همچنان در معرض خطر هستند، زیرا Bitcoin Core به‌صورت خودکار به‌روزرسانی نمی‌شود و کاربران باید نسخه جدید را دستی نصب کنند. گزارش‌های گذشته نشان داده‌اند که درصد قابل‌توجهی از نودها معمولاً از نسخه‌های قدیمی استفاده می‌کنند، موضوعی که اهمیت به‌روزرسانی منظم نرم‌افزار را برجسته می‌کند.

    Post summary

    CVE‑2024‑52911 is a high‑severity bug in Bitcoin Core that could let miners crash nodes via crafted blocks; the issue was disclosed with full technical details and fixed in version 29.0, with no evidence of active exploitation.

    00050136
    337 followersView on X
  • ₿ Lord Kristaps Kaupe  ($ is for sats)@kristapsk

    @Kruwed Which means you run Bitcoin Core 28 or older, which has CVE-2024-52911 script interpreter remote crash bug. https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/

    0004075
    2.3K followersView on X

Explore more