Bitcoin Core: The 2018 Bug That Could Have Broken the 21 Million Limit
In September 2018 a bug report showed Bitcoin's main software could be tricked into creating coins. It was patched in hours and never used.

Key numbers
7 hours
Report to public patch
1 year
Exposed to inflation
0 BTC
Fake bitcoin created
54% to 60%
Nodes unpatched, May 2019
At 14:57 UTC on Monday 17 September 2018, an encrypted email reached five software developers. Three of them, Pieter Wuille, Greg Maxwell and Wladimir van der Laan, worked on Bitcoin Core, the free program that runs most of the Bitcoin network. The other two worked on rival software for Bitcoin Cash, a breakaway coin. The sender signed off as "beardnboobies" and described a way to crash Bitcoin Core with a single specially built block.
Within three hours the Bitcoin Core team knew it was worse than a crash. The same flaw would let a miner create bitcoin out of nothing, the one thing Bitcoin is built to make impossible. That day one bitcoin cost about $6,500 and the whole network was worth roughly $112 billion, according to Blockchain.com price data. About 17.2 million coins existed, under a hard limit of 21 million. A bug that could quietly break that limit threatened the asset itself, not one company's balance sheet.
Nobody used it. A fix was public seven hours after the report. By the time the developers admitted the full danger on 20 September, more than half of Bitcoin's mining power had already upgraded. The hole had been open since March 2017, and the counterfeiting version of it for a full year.
Free AI assistant
AI that works, and proves it.
Ask Cynt how AI could help your business. Free to try.
Free AI assistant
What a node checks, and what it stopped checking
Bitcoin has no central bank or clearing house. Instead, thousands of computers called nodes each keep a full copy of the ledger and check every payment against the rules, like an auditor who re-adds every column instead of trusting the bank's total. Miners are the companies that bundle payments into blocks, the pages of that ledger. In 2018 each new block paid its miner 12.5 freshly created bitcoin, about $80,000. Nodes check every block. One that breaks a rule is thrown out, and the miner's reward goes with it.
The rule that matters here is the ban on the double spend: spending the same money twice. Bitcoin balances work more like a wallet of banknotes than a bank account. Every payment hands over specific earlier receipts, and each receipt can be spent once. The bug concerned a single payment that lists the same receipt twice, like handing a cashier the same $10 note twice and being credited with $20.
Bitcoin Core had a check for exactly that, added in 2011 by developer Matt Corallo. In October 2016 Corallo proposed skipping it when checking whole blocks, because a later step appeared to catch the same problem. His pull request, number 9049, was titled "Remove duplicatable duplicate-input check" and claimed to save about half a millisecond per block. Other developers reviewed it and it was merged on 10 November 2016. It shipped in Bitcoin Core 0.14.0 on 8 March 2017.
The later step was not a real check. It was a tripwire, an "assertion", that shuts the program down if something impossible happens. So from March 2017 a block containing a doubled receipt crashed every node running 0.14. Then version 0.15.0, released on 14 September 2017, rewrote how the software tracks unspent coins and changed the tripwire slightly. If the doubled receipt came from an earlier block, nothing tripped. The node accepted the payment and credited both halves. Money had been created.
Why printing bitcoin breaks everything
The 21 million limit is not a promise from a company. It is enforced by every node refusing any block that pays out more than the schedule allows. A node running 0.15 to 0.16.2 would have accepted counterfeit coins as real. A crypto exchange, which works like an online stockbroker, checking deposits with a vulnerable node would have credited them and let the depositor sell them for real dollars.
There were limits on the damage. Only a miner could pull it off, because a doubled receipt cannot travel across the network as an ordinary payment. And a miner who tried risked an $80,000 block reward if enough of the network rejected the block. Before the patch, every node on the then-current versions would have accepted it.
Bitcoin had been here once before. On 15 August 2010, a flaw let someone create more than 184 billion bitcoin in block 74,638. Satoshi Nakamoto, Bitcoin's anonymous creator, shipped a fix in about five hours and the network rewound past the bad block. In 2018 the network was worth $112 billion and had no founder to issue instructions.
Seven hours on 17 September
The timeline published by Bitcoin Core runs almost to the minute, all times UTC. At 15:15 Maxwell passed the report to Cory Fields, Suhas Daftuar, Alex Morcos and Corallo. At 17:47 Corallo worked out that the crash was also a counterfeiting bug. At 19:15 he started trying to reach Slush Pool, one of the largest mining pools. At 19:29 Maxwell timestamped a cryptographic fingerprint of a test proving the inflation flaw, a way to show later what the team knew and when, without revealing it.
At 20:15 John Newbery and James O'Beirne were brought in to warn companies that a patch was coming. At 20:30 Corallo gave the patch to Slush Pool's chief executive and chief technology officer, describing only the crash. Slush Pool confirmed it had upgraded at 20:48. Bitcoin ABC, the main Bitcoin Cash software, was told at 21:08 that a patch would go public before 22:00.
At 21:57 the fix went up as pull request 14247, described as a crash fix. Bitcoin ABC published its own patch a minute later. At 22:07 an advisory went out to members of Bitcoin Optech, an industry engineering group. Version 0.17.0rc4 was tagged at 23:21, and 0.16.3 at 00:24 on 18 September. Download files were ready at 20:44 that evening. Banners urging upgrades appeared on Bitcointalk and Reddit's r/Bitcoin an hour later.

Why they told half the truth
The fix was identical either way, so the developers chose to call it a crash fix. Their later notice said the decision was made "to encourage rapid upgrades" while companies and miners were quietly told to hurry. Bitcoin Optech said Wuille and Maxwell watched the network around the clock for any attempt to use the hidden flaw.
The secret could not last. The patch was public code, and anyone who read it carefully could work out what it closed. On 20 September a post on a public forum described the full impact and was quickly retracted, though not before others had copied it. At 19:50 the same day, a developer named David Jaenson independently found the inflation flaw and reported it to Bitcoin Core's security address. The full disclosure went up that day.
The finder was not pleased. On 21 September awemany, a pseudonymous developer for Bitcoin Unlimited and Bitcoin Cash, revealed himself as "beardnboobies" in a post titled "600 Microseconds", a jab at the time the 2016 change saved. The two camps had split in August 2017 after years of fighting over block sizes. He had found the bug in Bitcoin ABC's code, while porting features into Bitcoin Unlimited, then traced it back to Bitcoin Core. He called it "the most catastrophic bug in recent years". He raised and then set aside the idea of sabotage, blaming arrogance instead. He also accused Bitcoin Core of publishing the patch too openly, leaving Bitcoin Cash and the many coins built on copied Bitcoin code exposed.
The aftermath
The bug was never used on Bitcoin's main network. Bitcoin Core's notice said the team was "unaware of any attempts to exploit this vulnerability", and Bitcoin Optech later stated it was never exploited on mainnet. The record backs that up: every patched node that downloads Bitcoin's history from scratch re-checks every block back to 2009, and a block containing a doubled spend would make it reject the chain.
The test network was another matter. Around 27 September 2018 someone mined a block on testnet, Bitcoin's practice network where coins have no value, that used the bug. Alex Morcos of Chaincode Labs flagged it publicly. Old 0.14 nodes crashed. Nodes on 0.15 to 0.16.2 accepted the double spend, then could not undo it when the honest chain overtook them, and split off from everyone else. It was a live demonstration of what the main network had escaped.
Bitcoin Core released backported fixes, 0.14.3 and 0.15.2, on 28 September 2018, and 0.17.0 on 3 October. The release notes for 0.16.3 credited "beardnboobies"; the later ones credited "awemany (for CVE-2018-17144, previously credited as 'anonymous reporter')". awemany had put a Bitcoin Cash address in his report asking for a bounty. Bitcoin Core had no formal bounty programme, and he wrote on 21 September that nothing had arrived.
Upgrading was slow at the edges. In May 2019, eight months later, Bitcoin Core developer Luke Dashjr counted around 100,000 nodes and found between 54% and 60% still running vulnerable versions. Miners and exchanges, the parties that mattered most, had moved quickly. Hobbyists had not.
The official CVE record held by MITRE still describes CVE-2018-17144 only as a crash bug. In July 2024 Bitcoin Core published a written disclosure policy, with set waiting periods by severity, and released details of ten old, already fixed vulnerabilities on 3 July. Critical bugs, the class this one belongs to, are still handled case by case.
What this teaches
- A safety check removed to save half a millisecond left a counterfeiting hole open for a year. Speed changes to money-handling code need the same scrutiny as new features.
- A crash tripwire is not a rule. Once a later rewrite softened the tripwire, nothing stopped invalid blocks.
- Bitcoin's 21 million limit is only as strong as the software every node runs, so old, unpatched nodes are a network-wide risk.
- Partial disclosure bought about three days. A public patch can be reverse engineered, so quiet warnings to miners and exchanges must move faster than readers of the code.
- Rival developers found and responsibly reported the bug. Different teams reading the same code is a security asset, whatever they think of each other.
COMMENTS