Bitcoin Core Upgrade ‘Critical’ for Everyone, Urge Developers in Bug Disclosure

Published at: Sept. 21, 2018

Bitcoin Core developers published a “full disclosure” of the vulnerability affecting several implementations of the Bitcoin (BTC) client Friday, September 21, repeating calls for all nodes to upgrade to the latest version as a priority.

In addition to technical details about the bug, known as CVE-2018-17144, the disclosure explains how developers dealt with the threat to the Bitcoin network, along with a timeline of its discovery and patching in Bitcoin Core version 0.16.3.

“In order to encourage rapid upgrades, the decision was made to immediately patch and disclose the less serious Denial of Service vulnerability, concurrently with reaching out to miners, businesses, and other affected systems while delaying publication of the full issue to give times for systems to upgrade,” the notice reads.

CVE-2018-17144 had spooked the Bitcoin technical community when an anonymous party reported it this week, with Bitcoin.org creator Cobra describing its potential impact as “very scary.”

“At this time we believe over half of the Bitcoin hashrate has upgraded to patched nodes. We are unaware of any attempts to exploit this vulnerability,” the disclosure continues, adding:

“However, it still remains critical that affected users upgrade and apply the latest patches to ensure no possibility of large reorganizations, mining of invalid blocks, or acceptance of invalid transactions occurs.”

The impetus to upgrade at the current time appears not to be shared unanimously, with Bitcoin Core developer Luke-jr subsequently claiming the update publication was “premature.”

“[In my opinion] this is being disclosed way too prematurely (only 2% of the network has upgraded), but the cat's out of the bag,” he wrote on Twitter, nonetheless urging followers to upgrade “ASAP!”

Tags
Related Posts
Bitcoin.org blocks access to Bitcoin software download in the UK
It is no longer possible to download the Bitcoin Core software from Bitcoin.org if you visit the website with a United Kingdom internet protocol (IP) address. A notice on the website reads: “This software is presently not available for download in the UK, and download links will not work if you are located within the United Kingdom.” Indeed, attempting to proceed with downloading the Bitcoin (BTC) software from the site using a U.K. IP returns a “404 error.” Detailing the reason for blocking access to the software download for U.K. site visitors, Bitcoin.org’s pseudonymous owner Cøbra responded to a tweet …
Bitcoin / July 2, 2021
Would Bitcoin suffer if the lead maintainers were kidnapped by aliens?
It is a question that many in the crypto community must have asked themselves at least once. The news of Wladimir van der Laan taking a temporary hiatus, prompted us to explore what some might consider to be an improbable, yet highly impactful situation. A Bitcoin Core developer that is also a maintainer of the project's GitHub account (i.e., someone who can “merge code into the master branch”) is a rare commodity. To put this in perspective, if a Bitcoin Core developer is a black belt, then someone like van der Laan is a third-degree black belt. To set the …
Bitcoin / Sept. 11, 2020
Bitmain reportedly cuts off funding to Bitcoin Core developers
Bitmain, one of the world’s largest Bitcoin (BTC) miner producers, has reportedly halted its funding for some primary developers maintaining Bitcoin-related software. Jonas Schnelli, a major Bitcoin Core contributor and maintainer, claimed that Bitmain halted its support after funding his efforts for more than three years. In a Dec. 1 tweet, Schnelli said that he lost his sponsorship from Bitmain alongside Joao Barbosa, another Bitcoin Core contributor also known under the “Promag” nickname on GitHub. “Thanks Bitmain for all the help (despite the disagreement we had),” Schnelli tweeted, asking the crypto community to contribute to his further efforts on Bitcoin …
Bitcoin / Dec. 2, 2020
Sorry BitPay, New Bitcoin Upgrade Proposal Disables BIP70 by Default
Cryptocurrency payment processor BitPay may soon find it harder to do business as developers plan to remove support for the way it creates payment addresses. BitPay address support may disappear from Bitcoin In a GitHub discussion about the future 0.19.0 release of the Bitcoin Core client, developers continued plans to disable BIP70 by default, and possibly remove it altogether in a later version. The proposal first appeared in March this year, with activity to make it a reality ongoing. BitPay has stuck to using the payment address format defined in BIP70. Other wallets and payment businesses have joined the majority …
Bitcoin / Sept. 23, 2019
On Wallets and Safety, Part 1: Desktop Wallets
Nothing has changed since the funds in our possession have travelled from physical wallets made of leather and textile or porcelain piggybanks to online wallets created from intangible matters. The keeping principle is still the same – the secret and even intimate carrier has to be reliable, safe and private. No holes, especially cryptographic, can be tolerated. Types of Bitcoin Wallets Let us make the first stop at the types of wallets presented to the Bitcoin users. One of the widely used classifications divides all of them in three main groups: Desktop wallets. Mobile wallets. Internet wallets. Each has to …
Bitcoin / March 20, 2014