Bitcoin Core developers disclosed a high-severity memory denial-of-service flaw, tracked as CVE-2019-25220, that allowed attackers to crash vulnerable nodes by flooding them with long, low-difficulty header chains. The bug affected versions before 24.0.1 and was estimated to expose roughly 17% of the network at disclosure, with the cost of mounting the attack falling from about 4.12 BTC in 2019 to roughly 0.14 BTC by September 2024. Bitcoin Core said the issue was fixed in PR #25717, which added cumulative-work verification before storing headers in memory, while a later pre-synchronization bug was addressed in PR #26355.
The disclosure came alongside a broader push to address risks from outdated Bitcoin Core software, with developers publishing older fixed vulnerabilities that still affected a meaningful share of active nodes. Reported issues in legacy releases included censorship of unconfirmed transactions, netsplits, additional denial-of-service conditions, memory-related crashes, and less common flaws that could enable remote code execution or CPU and memory exhaustion. Bitcoin Core also adopted a formal security disclosure policy with low, medium, high, and critical severity tiers, aiming to improve transparency and pressure node operators to upgrade; one analysis cited about 787 active nodes still running versions older than 0.21.0.
See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting said a critical Bitcoin Core vulnerability still threatened more than 13% of nodes, underscoring continued exposure among operators running outdated software after disclosure and patch availability. This reflected the ongoing risk from lagging upgrades across the network.
Analysis of the disclosed header-spam vulnerability emphasized that malicious miners could use it to disrupt competing pools, reduce effective network hash rate, or create more favorable conditions for double-spending. By September 2024, the estimated attack cost had dropped to about 0.14 BTC.
Bitcoin Core published details of CVE-2019-25220, a high-severity memory exhaustion flaw affecting versions before 24.0.1 that could remotely crash peers. The disclosure said the attack cost had fallen over time, making exploitation increasingly practical against outdated nodes.
Later coverage of Bitcoin Core's older disclosed vulnerabilities said roughly 6% of active nodes were still running outdated software affected by issues including transaction censorship, denial of service, crashes, and less common remote code execution or resource exhaustion flaws. The reporting reiterated that the new disclosure policy was meant to improve transparency and drive upgrades.
Bitcoin Core developers introduced a formal security disclosure policy with four severity levels and disclosed multiple previously fixed vulnerabilities affecting outdated versions. The move was intended to improve transparency and push node operators to upgrade unsupported software.
The last vulnerable release line, Bitcoin Core 23.2, reached end of life, satisfying the project's policy condition for later public disclosure of the header-spam DoS issue. Older unsupported nodes remained exposed if not upgraded.
Bitcoin Core addressed a high-severity denial-of-service flaw that let attackers crash nodes by spamming extremely long low-difficulty header chains. The fix was implemented in PR #25717 and shipped in Bitcoin Core 24.0.1.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
keyhunters.ru
Open sourcecryptodnes.bg
Open sourcecoinspect.com
Open sourcebitcoincore.org
Open sourcecryptobriefing.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.