Bitcoin Core Closes PSBT Signing Edge Case That Could Let Payments Be Redirected Without Key Theft

AI Market Summary
Bitcoin Core merged a safeguard to prevent signing certain PSBTs using SIGHASH_SINGLE where outputs can be altered without invalidating signatures, enabling recipient redirection under edge conditions (not key theft). The change reduces wallet and hardware-signer authorization risk, but it is only in the development branch with no confirmed released/backported version yet, leaving near-term focus on wallet-side validation and signer policy.
Impact level
● Medium
Affected assets
BTC/USDT+2.04%
AI Insight · BTC/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Bitcoin Core has introduced a new safeguard to stop wallets and signers from producing signatures that may fail to lock funds to the recipient a user approved. The change was merged into Bitcoin Core's master development branch on Sept. 25 and was highlighted by Bitcoin Optech on Oct. 2. The issue sits in a narrow corner of partially signed Bitcoin transactions (PSBTs). It does not reveal private keys. Instead, it can create a scenario where a signature remains valid even if the transaction's recipient is altered under specific conditions, creating an authorization gap for users. At the center is SIGHASH_SINGLE, a signing mode intended to bind an input to the output at the same index. If the transaction lacks an output at that position, the protection can fail in different ways depending on the input type. For legacy inputs, the "missing output" condition can lead to a signature over a fixed hash value. Bitcoin Core developers said such a signature could potentially be reused against other unspent outputs controlled by the same key when the same structural conditions exist. SegWit v0 inputs are more constrained because the signature still commits to the specific coin being spent and its amount. Even so, the destination output can remain unbound, meaning software could show one payment destination to a user while generating a signature that does not cryptographically guarantee the approved recipient stays unchanged. Bitcoin Core previously rejected this edge case through its rawtransaction signing interface, but PSBT workflows could still sign it, including via walletprocesspsbt. The new patch moves the check into shared signature-creation logic. That prevents signing affected legacy and SegWit v0 inputs while still allowing other valid inputs in the same PSBT to proceed. PSBTs are widely used to coordinate transactions between software wallets, hardware devices, and offline signers, enabling transaction construction and signing without exposing private keys. The update reinforces a different boundary: signatures should commit to the transaction details the user actually authorized. Bitcoin Improvement Proposal (BIP) 174, which defines PSBTs, already advises signers to reject unacceptable signing modes and recommends SIGHASH_ALL when no alternative is specified. Bitcoin Core's change ensures this missing-output configuration is blocked before it reaches the signing stage. A production release containing the safeguard has not yet been confirmed. The patch landed in the development branch on Sept. 25, and as of Oct. 4, Bitcoin Core's release listings had not identified a fixed version or confirmed a backport. In the meantime, wallet providers and hardware-signing integrations face a near-term decision: audit and tighten their own handling of SIGHASH_SINGLE requests rather than waiting for a downstream Bitcoin Core release to enforce the same protection. The original report appeared on CryptoSlate.