• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Thursday, September 11, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

‘High’ Severity Bug in Bitcoin Software Revealed 2 Years After Fix

9 September 2020
in Blockchain
Reading Time: 3 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT


Cryptohopper
ADVERTISEMENT

A previously undisclosed vulnerability in the Bitcoin Core software could have allowed attackers to steal funds, delay settlements or split the largest blockchain network into conflicting versions had it not been quietly patched two years ago.

That’s according to a paper published Wednesday by Braydon Fuller, a protocol engineer at crypto shopping site Purse, who caught the vulnerability in June 2018, and Javed Khan, a core developer of the Handshake protocol.  

The vulnerability was given a severity level of 7.8 on a scale of 1 to 10, which is deemed “high” (9 or above is considered “critical”). It was caused by “remote nodes” failing to clear invalid transactions from their memory, Khan told CoinDesk. 

The inability to clear those transactions could lead to an aggressor flooding a victim node with stale data in what is referred to as “uncontrolled resource consumption,” eventually causing the node to shut down, the paper states.

Read more: Latest Bitcoin Core Code Release Protects Against Nation-State Attacks

“There was no mechanism to make sure that the pending details of a transaction are valid or not. In certain cases you could fill up the remote memory with invalid transactions,” Khan said.

No attempt to take advantage of the hole was found in the wild, Khan and Fuller wrote. The vulnerability could not be disclosed publicly for over two years as node operators took longer than expected to update, Fuller said.

While the vulnerability was fixed, its disclosure highlights the difficulties of building a global money standard on programming languages created by humans, not to mention the high technical barriers to engaging in development of the top cryptocurrency.

The vulnerability was introduced to Bitcoin Core in November 2017. Some 50% of Bitcoin nodes at the time were exposed to the attack vector, according to the paper. Earlier versions of Bitcoin Core were not affected.

Bitcoin Core and more

Khan further said that the vulnerability could have enabled an attacker to steal funds from nodes that had open channels on the Lightning Network, an experimental payment system built on top of the Bitcoin blockchain.

Bitcoin Core versions 0.16.0 and 0.16.1 were affected and patched by developer Matt Corallo following Fuller’s disclosure to the core team in July 2018. Corallo did not answer questions seeking comment by press time.

The discovery by Fuller (who has also worked as lead developer at decentralized cloud storage protocol Storj) was followed by another Bitcoin bug addressed two months later in Bitcoin Core 0.16.3. Also a vector for a denial-of-service attack, one aspect of that bug allowed miners to “inflate the supply of Bitcoin” as they could double-spend certain values, the Bitcoin Core team wrote at the time.

The emergency patch issued in that Bitcoin Core version addressed Fuller’s bug as well, Khan and Fuller wrote.

A spot was reserved for the resource consumption vulnerability on the National Institute of Standards and Technology’s Common Vulnerabilities and Exposures (CVE) registry as CVE-2018-17145 in 2018, but it has yet to be filled out. The registry acts as a public glossary for software bugs of note.

Bitcoin Core is the reference implementation, or standard version of the network software from which others are derived. According to the paper, the exploit was also possible on several other implementations of Bitcoin and its offshoots:

  • Bitcoin Knots v0.16.0
  • All beta versions of Bcoin up to v1.0.0-pre
  • All versions of Btcd up to v0.20.1-beta
  • Litecoin Core v0.16.0
  • Namecoin Core v0.16.1
  • All versions of Dcrd up to v1.5.1. 

All of these implementations have been patched.

UPDATE (Sept. 9, 13:30 UTC): Added a link to the paper and a more up-to-date company affiliation for Braydon Fuller.

Disclosure

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.



Source link

Related articles

Blockchain Powers Jack Ma’s -B Ant Group Energy Asset Strategy

Blockchain Powers Jack Ma’s $8-B Ant Group Energy Asset Strategy

9 September 2025
Japan Post Bank To Give Digital Yen Access To .3T Deposits

Japan Post Bank To Give Digital Yen Access To $1.3T Deposits

3 September 2025
[crypto-donation-box]
Tags: BitcoinBugFixhighRevealedSeveritysoftwareYears
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Huobi Launches Crypto Saving Products to Compete With DeFi Yield Farming

Next Post

This “Bitcoin bank” wants to offer a £40 million IPO in London

Related Posts

Blockchain Powers Jack Ma’s -B Ant Group Energy Asset Strategy

Blockchain Powers Jack Ma’s $8-B Ant Group Energy Asset Strategy

9 September 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure According to Bloomberg, Ant Digital Technologies has...

Japan Post Bank To Give Digital Yen Access To .3T Deposits

Japan Post Bank To Give Digital Yen Access To $1.3T Deposits

3 September 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Japan Post Bank is moving toward a...

The Blockchain Group Pushes Institutional Crypto Wave in Europe

The Blockchain Group Pushes Institutional Crypto Wave in Europe

10 June 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure A Bitcoin-focused company based in Paris wants...

Ripple And Japan’s Web3 Salon Spark Asia Innovation

Ripple And Japan’s Web3 Salon Spark Asia Innovation

10 June 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ripple has teamed up with Japan’s Web3...

Blockchain Could Revolutionize What We Eat, Study Reveals

Blockchain Could Revolutionize What We Eat, Study Reveals

5 June 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure A growing number of experts warn that...

Load More
Next Post

This "Bitcoin bank" wants to offer a £40 million IPO in London

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance

Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance

11 September 2025
SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?

SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?

11 September 2025
Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block

Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block

11 September 2025
Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action

Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action

11 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance
  • SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?
  • Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block
  • Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action
  • 78,229 Ethereum Leaves Kraken As 4 New Wallets Move ETH: Institutional Accumulation?

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,264.00
  • ethereumEthereum (ETH) $ 4,455.38
  • xrpXRP (XRP) $ 3.03
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 902.37
  • solanaSolana (SOL) $ 228.25
  • usd-coinUSDC (USDC) $ 0.999812
  • dogecoinDogecoin (DOGE) $ 0.256317
  • staked-etherLido Staked Ether (STETH) $ 4,446.07
  • tronTRON (TRX) $ 0.346560
  • cardanoCardano (ADA) $ 0.893062
  • wrapped-stethWrapped stETH (WSTETH) $ 5,396.46
  • chainlinkChainlink (LINK) $ 24.37
  • hyperliquidHyperliquid (HYPE) $ 56.55
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,800.54
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,073.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.66
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.394820
  • avalanche-2Avalanche (AVAX) $ 29.19
  • wrapped-eethWrapped eETH (WEETH) $ 4,789.81
  • bitcoin-cashBitcoin Cash (BCH) $ 596.54
  • wethWETH (WETH) $ 4,454.53
  • hedera-hashgraphHedera (HBAR) $ 0.239168
  • leo-tokenLEO Token (LEO) $ 9.62
  • litecoinLitecoin (LTC) $ 116.00
  • crypto-com-chainCronos (CRO) $ 0.259064
  • the-open-networkToncoin (TON) $ 3.19
  • usdsUSDS (USDS) $ 0.999801
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,222.00
  • polkadotPolkadot (DOT) $ 4.24
  • whitebitWhiteBIT Coin (WBT) $ 43.72
  • uniswapUniswap (UNI) $ 10.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • mantleMantle (MNT) $ 1.67
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.198911
  • ethenaEthena (ENA) $ 0.778329
  • moneroMonero (XMR) $ 271.09
  • aaveAave (AAVE) $ 309.03
  • bitget-tokenBitget Token (BGB) $ 4.92
  • pepePepe (PEPE) $ 0.000011
  • daiDai (DAI) $ 0.999267
  • okbOKB (OKB) $ 194.90
  • nearNEAR Protocol (NEAR) $ 2.75
  • bittensorBittensor (TAO) $ 357.84
  • jito-staked-solJito Staked SOL (JITOSOL) $ 280.54
  • ondo-financeOndo (ONDO) $ 1.06