High-Severity Bitcoin Core Flaw (CVE-2024-52911) Still Puts 43% of Nodes at Risk
ChainCatcher reports that Protos has highlighted a newly disclosed high-severity vulnerability in Bitcoin Core, tracked as CVE-2024-52911. The issue affects versions 0.14.1 through 28.4 and could allow miners to remotely crash other users' nodes and potentially execute code by mining specially crafted blocks.
Developer Cory Fields discovered and responsibly disclosed the flaw in November 2024. A fix was merged in December 2024 and shipped in April 2025 with the v29 release. The final vulnerable 28.x line reached end-of-life on April 19, 2026.
Because Bitcoin full-node upgrades are voluntary, an estimated 43% of nodes are still running outdated, vulnerable software. Protos notes the attack would be prohibitively expensive in practice: miners would need to commit significant hash power to producing invalid blocks that generate no block reward, making real-world exploitation unlikely.