🌳 The Merkle Tree Duplicate-Transaction Flaw
On 14 May 2012, the Merkle tree flaw catalogued as CVE-2012-2459 became public: with an odd number of hashes the last transaction is duplicated, letting an attacker craft an invalid block sharing a valid block's Merkle root and poison a node's invalidity cache — a textbook eclipse-attack vector against individual nodes. It was fixed quietly; no mainnet exploitation was ever recorded.
