• bitcoinBitcoin (BTC) $ 80,007.00
  • ethereumEthereum (ETH) $ 2,282.97
  • tetherTether (USDT) $ 0.999874
  • bnbBNB (BNB) $ 639.62
  • xrpXRP (XRP) $ 1.39
  • usd-coinUSDC (USDC) $ 0.999890
  • solanaSolana (SOL) $ 88.48
  • tronTRON (TRX) $ 0.348715
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • dogecoinDogecoin (DOGE) $ 0.106811
  • whitebitWhiteBIT Coin (WBT) $ 58.96
  • usdsUSDS (USDS) $ 0.999814
  • hyperliquidHyperliquid (HYPE) $ 42.53
  • cardanoCardano (ADA) $ 0.263868
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 574.80
  • leo-tokenLEO Token (LEO) $ 10.38
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 449.71
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 397.77
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.94
  • the-open-networkToncoin (TON) $ 2.58
  • canton-networkCanton (CC) $ 0.145375
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.158876
  • memecoreMemeCore (M) $ 3.67
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 0.999625
  • daiDai (DAI) $ 0.999577
  • litecoinLitecoin (LTC) $ 56.71
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.57
  • ethena-usdeEthena USDe (USDE) $ 0.999445
  • hedera-hashgraphHedera (HBAR) $ 0.090647
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.979709
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007534
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999872
  • crypto-com-chainCronos (CRO) $ 0.069625
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 307.56
  • tether-goldTether Gold (XAUT) $ 4,711.51
  • global-dollarGlobal Dollar (USDG) $ 0.999900
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.074071
  • pax-goldPAX Gold (PAXG) $ 4,715.22
  • uniswapUniswap (UNI) $ 3.49
  • polkadotPolkadot (DOT) $ 1.31
  • mantleMantle (MNT) $ 0.667286
  • nearNEAR Protocol (NEAR) $ 1.54
  • ondo-financeOndo (ONDO) $ 0.399485
  • skySky (SKY) $ 0.080662
  • okbOKB (OKB) $ 85.41
  • falcon-financeFalcon USD (USDF) $ 0.998002
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pi-networkPi Network (PI) $ 0.168546
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • internet-computerInternet Computer (ICP) $ 3.11
  • aster-2Aster (ASTER) $ 0.660437
  • ripple-usdRipple USD (RLUSD) $ 0.999903
  • ethereum-classicEthereum Classic (ETC) $ 9.43
  • bitget-tokenBitget Token (BGB) $ 2.10
  • usddUSDD (USDD) $ 0.999760
  • aaveAave (AAVE) $ 92.57
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bfusdBFUSD (BFUSD) $ 0.999400
  • morphoMorpho (MORPHO) $ 2.09
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • algorandAlgorand (ALGO) $ 0.128871
  • kucoin-sharesKuCoin (KCS) $ 8.32
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • ethenaEthena (ENA) $ 0.123390
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.101483
  • quant-networkQuant (QNT) $ 73.38
  • united-stablesUnited Stables (U) $ 0.999867
  • render-tokenRender (RENDER) $ 1.98
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • kaspaKaspa (KAS) $ 0.035930
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.77
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.07
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.87
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.889215
  • worldcoin-wldWorldcoin (WLD) $ 0.257178
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • aptosAptos (APT) $ 1.06
  • filecoinFilecoin (FIL) $ 1.09
  • wbnbWrapped BNB (WBNB) $ 759.61
  • arbitrumArbitrum (ARB) $ 0.132981
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • gatechain-tokenGate (GT) $ 7.25
  • siren-2Siren (SIREN) $ 1.10
  • stable-2​​Stable (STABLE) $ 0.032698
  • pump-funPump.fun (PUMP) $ 0.002035
  • justJUST (JST) $ 0.083976
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • jupiter-exchange-solanaJupiter (JUP) $ 0.213036
  • flare-networksFlare (FLR) $ 0.007823
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010329
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.007504
  • dashDash (DASH) $ 50.02
  • usdtbUSDtb (USDTB) $ 0.999577
  • venice-tokenVenice Token (VVV) $ 13.55
  • beldexBeldex (BDX) $ 0.080175
  • bonkBonk (BONK) $ 0.000007
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ousgOUSG (OUSG) $ 115.17
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.921275
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • skyaiSkyAI (SKYAI) $ 0.596637
  • xdce-crowd-saleXDC Network (XDC) $ 0.029536
  • ghoGHO (GHO) $ 0.999925
  • clbtcclBTC (CLBTC) $ 76,920.00
  • usual-usdUsual USD (USD0) $ 0.998168
  • hash-2Provenance Blockchain (HASH) $ 0.010560
  • official-trumpOfficial Trump (TRUMP) $ 2.39
  • dexeDeXe (DEXE) $ 11.65
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000097
  • yldsYLDS (YLDS) $ 0.999915
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • midnight-3Midnight (NIGHT) $ 0.031645
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.225338
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • a7a5A7A5 (A7A5) $ 0.012909
  • tbtctBTC (TBTC) $ 70,942.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.53
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • true-usdTrueUSD (TUSD) $ 0.999767
  • blockstackStacks (STX) $ 0.259913
  • megausdMegaUSD (USDM) $ 0.999627
  • chilizChiliz (CHZ) $ 0.044309
  • edgexedgeX (EDGE) $ 1.28
  • euro-coinEURC (EURC) $ 1.18
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • aerodrome-financeAerodrome Finance (AERO) $ 0.450755
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • sei-networkSei (SEI) $ 0.061922
  • usdgoUSDGO (USDGO) $ 1.00
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • tezosTezos (XTZ) $ 0.382101
  • injective-protocolInjective (INJ) $ 4.12
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • adi-tokenADI (ADI) $ 3.91
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999408
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • spx6900SPX6900 (SPX) $ 0.424619
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • monadMonad (MON) $ 0.033373
  • sun-tokenSun Token (SUN) $ 0.020141
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.387356
  • celestiaCelestia (TIA) $ 0.413881
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • usxUSX (USX) $ 0.999806
  • build-onBUILDon (B) $ 0.374541
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • curve-dao-tokenCurve DAO (CRV) $ 0.246925
  • kite-2Kite (KITE) $ 0.164203
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • layerzeroLayerZero (ZRO) $ 1.44
  • kinesis-goldKinesis Gold (KAU) $ 151.79
  • ether-fiEther.fi (ETHFI) $ 0.432317
  • pendlePendle (PENDLE) $ 2.08
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • flokiFLOKI (FLOKI) $ 0.000036
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • gnosisGnosis (GNO) $ 130.57
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • conflux-tokenConflux (CFX) $ 0.065670
  • lido-daoLido DAO (LDO) $ 0.400270
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • apxusdapxUSD (APXUSD) $ 0.999759
  • decredDecred (DCR) $ 19.16
  • doublezeroDoubleZero (2Z) $ 0.094230
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • optimismOptimism (OP) $ 0.151129
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • starknetStarknet (STRK) $ 0.054454
  • hastra-primePRIME (PRIME) $ 1.04
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • unibaseUnibase (UB) $ 0.126957
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Bitcoin bug allowed miners to run code on other people’s nodes

0 0


Bitcoin Core developers today disclosed a bug that has allowed miners to remotely crash and execute code on other people’s nodes.

The vulnerability, CVE-2024-52911, has affected Bitcoin Core 0.14.1 through 28.4. Developer Cory Fields responsibly disclosed and helped patch the high severity error via Pull Request (PR) 31112.

Had a miner wanted to utilize the dark trick, they could have executed software code on assorted nodes across the globe.

Fortunately, the bug remained obscure and likely not utilized due to its incredibly expensive attack vector.

Specifically, the attack required a miner to direct electricity-guzzling hashpower toward mining special types of blocks. A guaranteed opportunity cost, these invalid blocks could not become eligible for an actual coinbase reward to recoup the miners’ electricity costs.

Still, the mechanism of attack is easy to understand, albeit expensive to conduct.

We’ve been publishing Bitcoin Core security advisories for ~2 years now, and (afaik) we just disclosed the first ever memory safety issue: A use-after-free in the validation engine.

Credit to Cory Fields from the DCI for finding and reporting.

— Niklas Gögge (@dergoegge) May 5, 2026

A miner that produced a specially crafted block with sufficient proof-of-work could either crash victim nodes and/or use the crash to overtake its memory for remote code execution.

Bitcoin Core admitted that remote code execution was possible, although it did not cite specific examples of it occurring. It highlighted not only its cost and old age, but also the constraints on block data that have made it historically unlikely that miners engaged in meaningful episodes of puppeteering.

Old Bitcoin nodes still at risk of bug

Bitcoin Core’s advisory describes the bug as a script interpreter crash. During block validation, Bitcoin Core software pre-calculates and caches transaction input data, then dispatches script validation work to background threads that use computer memory.

If subjected to a CVE-2024-52911 attack, the node could keep reading from its cached memory after that data had already been freed from memory by another process.

Because this attack is a use-after-free memory bug, remote code execution is possible during this abnormal memory state.

In particular, remote code execution could occur when the node’s background script thread read cached, precomputed transaction data after it had been destroyed by a script validation, CScriptCheck.

Because upgrading a Bitcoin full node is voluntary and software updates are not automatic, a not insignificant minority of the network has delayed upgrading to version 29 (v29) or above.

Specifically, according to one popular estimate, as much as 43% of Bitcoin nodes are still running vulnerable full node software based on pre-v29 code.

Bitcoin Core pulls v30 downloads over bug that can scrub Satoshi-era wallets

Responsible disclosure in 2024

As early as November 2024, Cory Fields detected and privately reported the bug.

Four days after detection, Pieter Wuille pushed a fix proposal as PR 31112, titled “Improve parallel script validation error debug logging.”

The advisory purposefully read like a mundane, maintenance-style plumbing fix. Raising no alarm bells, it fixed Bitcoin Core’s check queue return handling and script validations.

Quickly, the PR by Fields and Wuille gained technical consensus for a merge into production by December 2024. Bitcoin Core 29.0 shipped with the fix by April 2025, and the final vulnerable release line, versions 28.x, reached end-of-life on April 19, 2026.

Now that node operators have had many months to upgrade, and in keeping with a policy in recent years of publicly disclosing old, previously secret bug fixes, Bitcoin Core finally announced the bug today on its website.

Bitcoin Core developer Niklas Gögge correctly noted that this is “the first ever memory safety issue” bug in Bitcoin Core. He thanked Fields for his responsible disclosure.

Bitcoin’s consensus rules were not changed by the bug fix. The bug was in node software and its use of computer memory checks, and the fix is already in current Bitcoin Core releases v29 and later.



Source link

Leave A Reply

Your email address will not be published.