CVE-2017-9230 describes a theoretical attack methodology against the Bitcoin Proof-of-Work algorithm, affecting Bitcoin products. This vulnerability, rated High severity with a CVSS score of 7.5, stems from a potential manipulation of 80-byte block headers that could reduce the difficulty of evaluating the Proof-of-Work function, violating security assumptions. While some consider it a benign mining optimization rather than a true vulnerability, it has a high confidentiality impact (C:H). There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it has generated some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:bitcoin:bitcoin:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.