CryptoMediaClub
Friday, December 12, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
  • en English
    • ar العربية
    • zh-CN 简体中文
    • cs Čeština‎
    • nl Nederlands
    • en English
    • et Eesti
    • fr Français
    • de Deutsch
    • iw עִבְרִית
    • it Italiano
    • ja 日本語
    • ko 한국어
    • lv Latviešu valoda
    • pl Polski
    • pt Português
    • ru Русский
    • sk Slovenčina
    • es Español
    • sv Svenska
    • uk Українська
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
  • en English
    • ar العربية
    • zh-CN 简体中文
    • cs Čeština‎
    • nl Nederlands
    • en English
    • et Eesti
    • fr Français
    • de Deutsch
    • iw עִבְרִית
    • it Italiano
    • ja 日本語
    • ko 한국어
    • lv Latviešu valoda
    • pl Polski
    • pt Português
    • ru Русский
    • sk Slovenčina
    • es Español
    • sv Svenska
    • uk Українська
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home Analysis

6% of Bitcoin nodes running outdated software vulnerable to exploits

12.07.2024
A A
0
127
VIEWS
ShareShare

Bitcoin Core developers have historically disclosed just 10 vulnerabilities affecting older software versions, as reported by Bitcoin Optech. The vulnerabilities, fixed in more recent releases, could have allowed various attacks on nodes running outdated Bitcoin Core versions.

The vulnerabilities are relevant given that Bitcoin Core developers recently introduced a new security disclosure policy to improve transparency and communication regarding vulnerabilities. Historically, the project has faced criticism for inadequate public disclosure of security-critical bugs, leading to a perception that Bitcoin Core is free of bugs.

Libbitcoin developer Eric Voskuil wrote, in a message to the Bitcoin mailing list, that this perception is misleading and potentially hazardous, as it underestimates the risks of running outdated software versions.

Active Bitcoin node vulnerabilities

CryptoSlate has analyzed active Bitcoin nodes to identify how many are currently vulnerable to each attack vector. Roughly 787 (5.94%) out of 14,001 nodes run versions older than 0.21.0.

The network remains secure and resistant to any meaningful attacks. Yet, this figure is significant enough to be considered a problem the Bitcoin community may need to address. Efforts can be made to encourage these node operators to upgrade to newer versions to enhance the Bitcoin network’s overall security, efficiency, and future readiness.

While not an immediate critical issue, it is undoubtedly a concern that warrants attention. It’s not an existential threat to Bitcoin, as most of the network still runs up-to-date software. However, it represents a non-trivial portion of the network that could cause issues or be exploited under certain circumstances. It indicates a need for better communication and incentives within the Bitcoin community to encourage more frequent updates.

Risks for active Bitcoin nodes

Vulnerability Affected Versions Vulnerable Nodes
Remote code execution due to a bug in miniupnpc (CVE-2015-6031) Before 0.11.1 22
Node crash DoS from multiple peers with large messages (CVE-2015-3641) Before 0.10.1 5
Censorship of unconfirmed transactions Before 0.21.0 787
Unbound ban list CPU/memory DoS (CVE-2020-14198) Before 0.20.1 185
Netsplit from excessive time adjustment Before 0.21.0 787
CPU DoS and node stalling from orphan handling Before 0.18.0 70
Memory DoS from large inv messages Before 0.20.0 182
Memory DoS using low-difficulty headers Before 0.15.0 29
CPU-wasting DoS due to malformed requests Before 0.20.0 182
Memory-related crash in attempts to parse BIP72 URIs Before 0.20.0 182

Per the disclosure, the most widespread vulnerability affected versions prior to 0.21.0, potentially impacting 787 nodes. This flaw could enable censorship of unconfirmed transactions and cause netsplits due to excessive time adjustments.

Three separate vulnerabilities affected versions before 0.20.0, each potentially impacting 182 nodes. These included a memory DoS from large inv-messages, a CPU-wasting DoS from malformed requests, and a memory-related crash when parsing BIP72 URIs.

An unbound ban list CPU/memory DoS vulnerability (CVE-2020-14198) affected versions prior to 0.20.1, potentially putting 185 nodes at risk. Earlier versions were susceptible to other attacks, such as a CPU DoS and node stalling from orphan handling (before 0.18.0, affecting 70 nodes) and a memory DoS using low-difficulty headers (before 0.15.0, impacting 29 nodes).

The oldest vulnerabilities disclosed included a remote code execution bug in miniupnpc (CVE-2015-6031) affecting versions before 0.11.1 and a node crash DoS from large messages (CVE-2015-3641) in versions prior to 0.10.1. These affected 22 and 5 nodes, respectively, indicating that very few are still running such outdated software.

New Bitcoin developer disclosure policy

The new policy categorizes vulnerabilities into four severity levels: low, medium, high, and critical. Low-severity bugs, which are difficult to exploit or have minimal impact, will be disclosed two weeks after a fixed version is released, with a pre-announcement made simultaneously.

Medium and high-severity bugs, which have more significant impacts, will be disclosed two weeks after the last affected release reaches its end-of-life (EOL), typically one year after the fixed version is first released. A pre-announcement will be made two weeks before disclosure. Critical bugs threatening the network’s integrity will require an ad-hoc disclosure procedure.

The policy will be implemented gradually. All vulnerabilities fixed in Bitcoin Core versions 0.21.0 and earlier will be disclosed immediately. In July, vulnerabilities fixed in version 22.0 will be disclosed, followed by those fixed in version 23.0 in August. This process will continue until all EOL versions have been addressed.

This initiative aims to set clear expectations for security researchers, incentivizing them to find and responsibly disclose vulnerabilities. By making security bugs available to a broader group of contributors, the policy seeks to prevent future issues and enhance the overall security of the Bitcoin network.

Per the Bitcoin Development Mailing List, the policy’s gradual adoption will allow the community to adjust and provide feedback on its impact.

Node operators still using affected versions are strongly advised to upgrade to the latest release to mitigate these potential risks.

The post 6% of Bitcoin nodes running outdated software vulnerable to exploits appeared first on CryptoSlate.

Share10Tweet6ShareSharePin2

Related Posts

Bitcoin flashes rare liquidity warning because the Fed’s $40 billion “stimulus” is actually a trap
Analysis

Bitcoin flashes rare liquidity warning because the Fed’s $40 billion “stimulus” is actually a trap

12.12.2025
0

Bitcoin has a historical tendency to punish consensus, but the price action following the Federal Reserve’s December meeting offered a...

Read moreDetails
A new loophole just proved you don’t actually own your shares – but the fix is already live on Solana

A new loophole just proved you don’t actually own your shares – but the fix is already live on Solana

11.12.2025
Crypto market adds $150 billion in 24 hours: Why is Bitcoin up today?

Crypto market adds $150 billion in 24 hours: Why is Bitcoin up today?

10.12.2025
Has Congress quietly forced the Department of War to use Bitcoin to bankrupt Chinese hackers?

Has Congress quietly forced the Department of War to use Bitcoin to bankrupt Chinese hackers?

09.12.2025
Bitcoin is tracking a hidden $400 billion Fed liquidity signal that matters more than rate cuts

Bitcoin is tracking a hidden $400 billion Fed liquidity signal that matters more than rate cuts

08.12.2025
Load More
Next Post
Best Crypto to Buy Now July 12 – Mantra, Maker, Shiba Shootout

Best Crypto to Buy Now July 12 – Mantra, Maker, Shiba Shootout

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

Blur NFT lending surpasses $16M in loans, led by Machi Big Brother

Blur NFT lending surpasses $16M in loans, led by Machi Big Brother

3 years ago
South Korean Parliament ‘Poised to Approve Tokenized Securities Bill’

South Korean Parliament ‘Poised to Approve Tokenized Securities Bill’

6 months ago
ETF filings changed the Bitcoin narrative overnight — Ledger CEO

ETF filings changed the Bitcoin narrative overnight — Ledger CEO

2 years ago
Top Crypto Gainers Today on DEXScreener – FELON, YIELD, BOOB

Top Crypto Gainers Today on DEXScreener – FELON, YIELD, BOOB

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Standard Chartered and AirAsia Parent Explore Ringgit-Backed Stablecoin

Trump’s Crypto Regulator Pick Heads to Senate Floor for Crucial Vote

Polish Government Defies President, Reintroduces Identical Crypto Law

Korean Authorities Claim Binance Partially Complied in Freezing Upbit Hack Funds

[LIVE] Crypto News Today: Latest Updates for Dec. 12, 2025 – Crypto Market Edges Higher; L2s Outperform While ETH Holds Tight Near $3.2K

Asia Market Open: Bitcoin Ticks Up As Asian Markets Gain After S&P 500 Record

Trending

Bitcoin at $90K After House Letter – SEC Faces New 401(k) Crypto Deadline
All news

Bitcoin at $90K After House Letter – SEC Faces New 401(k) Crypto Deadline

12.12.2025
0

The House Financial Services Committee sent a letter to the SEC on December 12, 2025, urging the...

Bitcoin flashes rare liquidity warning because the Fed’s $40 billion “stimulus” is actually a trap

Bitcoin flashes rare liquidity warning because the Fed’s $40 billion “stimulus” is actually a trap

12.12.2025
Bybit Launches Limited Edition BTC Staking Event For New Users

Bybit Launches Limited Edition BTC Staking Event For New Users

12.12.2025
Standard Chartered and AirAsia Parent Explore Ringgit-Backed Stablecoin

Standard Chartered and AirAsia Parent Explore Ringgit-Backed Stablecoin

12.12.2025
Trump’s Crypto Regulator Pick Heads to Senate Floor for Crucial Vote

Trump’s Crypto Regulator Pick Heads to Senate Floor for Crucial Vote

12.12.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz