Wednesday, September 09, 2020 12:31:58 PM
Sep 9, 2020 at 13:00 UTC
Updated Sep 9, 2020 at 13:58 UTC
https://www.coindesk.com/high-severity-bug-in-bitcoin-software-revealed-2-years-after-fix
A previously undisclosed vulnerability in the Bitcoin Core software could have allowed attackers to steal funds, delay settlements or split the largest blockchain network into conflicting versions had it not been quietly patched two years ago.
That’s according to a paper published Wednesday by Braydon Fuller, a protocol engineer at crypto shopping site Purse, who caught the vulnerability in June 2018, and Javed Khan, a core developer of the Handshake protocol.
The vulnerability was given a severity level of 7.8 on a scale of 1 to 10, which is deemed “high” (9 or above is considered “critical”). It was caused by “remote nodes” failing to clear invalid transactions from their memory, Khan told CoinDesk.
The inability to clear those transactions could lead to an aggressor flooding a victim node with stale data in what is referred to as “uncontrolled resource consumption,” eventually causing the node to shut down, the paper states.
Read more: Latest Bitcoin Core Code Release Protects Against Nation-State Attacks
“There was no mechanism to make sure that the pending details of a transaction are valid or not. In certain cases you could fill up the remote memory with invalid transactions,” Khan said.
No attempt to take advantage of the hole was found in the wild, Khan and Fuller wrote. The vulnerability could not be disclosed publicly for over two years as node operators took longer than expected to update, Fuller said.
While the vulnerability was fixed, its disclosure highlights the difficulties of building a global money standard on programming languages created by humans, not to mention the high technical barriers to engaging in development of the top cryptocurrency.
The vulnerability was introduced to Bitcoin Core in November 2017. Some 50% of Bitcoin nodes at the time were exposed to the attack vector, according to the paper. Earlier versions of Bitcoin Core were not affected.
Bitcoin Core and more
Khan further said that the vulnerability could have enabled an attacker to steal funds from nodes that had open channels on the Lightning Network, an experimental payment system built on top of the Bitcoin blockchain.
Bitcoin Core versions 0.16.0 and 0.16.1 were affected and patched by developer Matt Corallo following Fuller’s disclosure to the core team in July 2018. Corallo did not answer questions seeking comment by press time.
The discovery by Fuller (who has also worked as lead developer at decentralized cloud storage protocol Storj) was followed by another Bitcoin bug addressed two months later in Bitcoin Core 0.16.3. Also a vector for a denial-of-service attack, one aspect of that bug allowed miners to “inflate the supply of Bitcoin” as they could double-spend certain values, the Bitcoin Core team wrote at the time.
The emergency patch issued in that Bitcoin Core version addressed Fuller’s bug as well, Khan and Fuller wrote.
A spot was reserved for the resource consumption vulnerability on the National Institute of Standards and Technology’s Common Vulnerabilities and Exposures (CVE) registry as CVE-2018-17145 in 2018, but it has yet to be filled out. The registry acts as a public glossary for software bugs of note.
Bitcoin Core is the reference implementation, or standard version of the network software from which others are derived. According to the paper, the exploit was also possible on several other implementations of Bitcoin and its offshoots:
* Bitcoin Knots v0.16.0
* All beta versions of Bcoin up to v1.0.0-pre
* All versions of Btcd up to v0.20.1-beta
* Litecoin Core v0.16.0
* Namecoin Core v0.16.1
* All versions of Dcrd up to v1.5.1.
All of these implementations have been patched.
UPDATE (Sept. 9, 13:30 UTC): Added a link to the paper and a more up-to-date company affiliation for Braydon Fuller.
Recent BTCUSD News
- Solana Eyes ‘Clear Path’ Towards $115 Amid SEC Guidance, SOL ETFs Demand • NEWSBTC • 03/19/2026 06:00:33 AM
- Crypto traders eye ‘bullish relief rally’ after Fed holds rates steady • Cointelegraph • 03/19/2026 05:23:40 AM
- Bitcoin Long-Term MVRV Remains In ‘Opportunity’ Zone: Data • NEWSBTC • 03/19/2026 05:00:17 AM
- Sen. Lummis Predicts Crypto Market Structure Markup In April, Senate Passage By Year-End • NEWSBTC • 03/19/2026 04:00:24 AM
- Polymarket buys DeFi startup Brahma in latest acquisition wave • Cointelegraph • 03/19/2026 03:33:50 AM
- California court dismisses Coinbase user’s challenge to IRS summons • Cointelegraph • 03/19/2026 03:26:34 AM
- SEC gives go-ahead to Nasdaq for tokenized trading trial • Cointelegraph • 03/19/2026 02:45:44 AM
- Jack Dorsey’s Block brings back a few workers after mass layoffs • Crypto Briefing • 03/19/2026 02:05:18 AM
- Fold Q4 revenue up, CEO sees Bitcoin rewards overtaking air miles • Cointelegraph • 03/19/2026 02:02:08 AM
- Ripple’s $500M Raise And Institutional Ties Keep XRP Firmly In Place • NEWSBTC • 03/19/2026 02:00:04 AM
- Ethereum Explodes 24% After Key Breakout: Rally To $4,956 In Play? • NEWSBTC • 03/19/2026 01:00:11 AM
- XRP Price Projections Soar To $15-$30 On CLARITY Act Prospects And Bank Adoption • NEWSBTC • 03/19/2026 12:29:24 AM
- Erik Voorhees’ Venice rolls out end-to-end encrypted AI modes, VVV token surges 10% • Crypto Briefing • 03/19/2026 12:09:40 AM
- Bitcoin falls under $71K but data shows BTC’s bullish momentum holding • Cointelegraph • 03/18/2026 11:23:32 PM
- Bitcoin Stalls Near $75K As Traders Move Coins To Exchanges • NEWSBTC • 03/18/2026 11:00:46 PM
- Strategy’s Bitcoin Holdings Cross 760,000 BTC, AI Reveals How Long Till It Gets To The 1 Million Mark • NEWSBTC • 03/18/2026 10:00:14 PM
- Here’s what happened in crypto today • Cointelegraph • 03/18/2026 09:55:09 PM
- Fed leaves rates unchanged, says geopolitical uncertainty clouds outlook • Cointelegraph • 03/18/2026 09:30:14 PM
- Nasdaq Gets Green Light For Tokenized Securities Trading After SEC Approval • NEWSBTC • 03/18/2026 09:09:21 PM
- Kalshi CEO fires back against Arizona criminal charges as ‘total overstep‘ • Cointelegraph • 03/18/2026 09:07:16 PM
- Best hardware wallets 2026: Ledger vs Trezor vs SafePal vs NGRAVE • Crypto Briefing • 03/18/2026 08:55:44 PM
- Bitcoin Monthly Timeframe Signals A Potential Market Shift • NEWSBTC • 03/18/2026 08:30:12 PM
- SEC approves tokenized securities to trade alongside traditional stocks • Crypto Briefing • 03/18/2026 08:20:23 PM
- SEC Chair explains why NFTs fall outside of securities laws • Cointelegraph • 03/18/2026 08:19:15 PM
- Visa unveils CLI tool to enable AI agents to execute card payments • Crypto Briefing • 03/18/2026 08:14:09 PM
Advances in Domestic Heavy Rare Earth Minerals Production Essential for North American Defense Stockpiles • ALOY • Mar 18, 2026 9:00 AM
ECGI Advances $10M Mortgage Tokenization Pilot as SEC Interpretation Adds Clarity • ECGI • Mar 18, 2026 8:45 AM
ECGI Advances Mortgage Tokenization Pilot as Institutional Market Rails Continue to Develop • ECGI • Mar 17, 2026 8:30 AM
Record Gold Prices Reshape Economics of New Mine Development • SNWGF • Mar 16, 2026 10:46 AM
Cannabix Technologies Announces Commercial Launch of Marijuana Breath Test (MBT) • BLOZF • Mar 16, 2026 8:37 AM
Exxe Group Advances Platform Strategy and Share Structure Reduction Following Strategic Meetings • AXXA • Mar 11, 2026 1:03 PM
