Critical Bitcoin Core Vulnerability CVE-2024-52911 Exposes 43% of Nodes to Attack
Severity: Medium (Score: 57.8)
Sources: Kucoin, Chaincatcher
Summary
Bitcoin Core developers disclosed a high-risk vulnerability, CVE-2024-52911, affecting versions 0.14.1 to 28.4. This flaw allows miners to remotely crash other users' nodes and execute code by mining specially crafted blocks. Discovered by Cory Fields in November 2024, the fix was merged in December and released in April 2025. Despite the patch, approximately 43% of Bitcoin nodes remain vulnerable as upgrading is voluntary. The last vulnerable version was discontinued on April 19, 2026. While the attack cost is high, the potential for exploitation remains a concern for those running outdated software. Key Points: • CVE-2024-52911 affects Bitcoin Core versions 0.14.1 to 28.4, allowing remote node crashes. • 43% of Bitcoin nodes are still running vulnerable software despite the availability of a patch. • The vulnerability was responsibly disclosed in November 2024 and patched in April 2025.
Key Entities
- Zero-day Exploit (attack_type)
- Bitcoin Core (platform)
- CVE-2024-52911 (cve)
- CWE-94 - Code Injection (cwe)