Bitcoin Core has introduced a defense mechanism preventing the signing of transactions that might fail to secure funds to a user-authorized payment destination.
Integrated into Bitcoin Core’s master development branch on Sept. 25, the update addresses a specific vulnerability in partially signed Bitcoin transactions (PSBTs) that could generate a legitimate signature without securing the intended output.
The adjustment was spotlighted by Bitcoin Optech on Oct. 2. While the vulnerability does not compromise a user’s private key, it presents an alternate danger: a signature can stay valid even if the transaction’s recipient is altered under certain circumstances.
The vulnerability centers on SIGHASH_SINGLE, a signing configuration meant to bind an input to its matching output position. If that position lacks an output, the security fails in varying ways depending on the variety of Bitcoin being spent.
For legacy inputs, the absence of an output can result in a signature based on a constant hash value. Developers at Bitcoin Core noted that this signature could potentially be reused against other unspent outputs managed by the identical key under matching structural conditions.
SegWit v0 transactions maintain more robust safeguards because the signature continues to bind to the specific coin being spent along with its value. Nonetheless, the recipient output can remain unbound.
This introduces an authorization dilemma for signing tools and wallets, where software might display one payment to a user while generating a signature that lacks cryptographic assurance that the approved recipient stays unmodified.
Bitcoin Core blocks the risky signing request
Although Bitcoin Core’s raw-transaction signing interface previously declined this edge case, its PSBT workflow—incorporating walletprocesspsbt—was still capable of signing it.
The updated code relocates the validation into the shared signature-generation logic of Bitcoin Core, blocking vulnerable legacy and SegWit v0 inputs from receiving signatures while permitting other valid inputs within the same PSBT to move forward.
PSBTs are frequently utilized for managing transactions across software wallets, offline signers, and hardware devices, enabling transaction creators to transmit data to an external signer without surrendering private key control to that device.
Consequently, the patch strengthens a separation that wallet creators must uphold independently of key security: a legitimate cryptographic signature must bind to the exact transaction specifics approved by the user.
Bitcoin Improvement Proposal 174, which outlines PSBTs, already instructs signers to decline unapproved signing configurations and advises utilizing SIGHASH_ALL when no alternative is designated. The update from Bitcoin Core actively blocks this output-missing setup from progressing to the signature phase.
End users do not yet have access to a verified production build featuring the protection. The Sept. 25 update was integrated into the development branch of Bitcoin Core, whereas the official release catalog of the project had not yet specified a patched release or verified backport as of Oct. 4.
This places the immediate responsibility on hardware-signing integrations and wallet developers to evaluate their personal processing of SIGHASH_SINGLE queries rather than depending on a Bitcoin Core release to implement equivalent security downstream.





