Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Bitcoin Core Adds Safeguard Against PSBT Signing Flaw

Bitcoin Core's development branch now includes a fix blocking a narrow vulnerability in partially signed transactions that could allow fund redirection without compromising private keys.
2 hours ago 18 views
Bitcoin Core Adds Safeguard Against PSBT Signing Flaw

Bitcoin Core has merged a safeguard into its development branch to address a signing vulnerability in partially signed Bitcoin transactions, or PSBTs. The change, merged on September 25, targets a flaw that could produce a valid signature without cryptographically binding funds to the payment destination a user approved.

The issue involves the SIGHASH_SINGLE signing mode, which is designed to commit an input to a corresponding output position. When a transaction lacks an output at that position, the protection breaks down differently depending on the type of Bitcoin being spent.

For legacy inputs, the missing-output case can produce a signature over a fixed hash value. Bitcoin Core developers noted that this signature may then be reusable against other unspent outputs controlled by the same key when similar structural conditions are present. SegWit v0 transactions retain stronger protections because the signature still commits to the specific coin being spent and its amount, though the destination output can remain unbound.

This creates an authorization problem for wallets and signing devices: software could present one payment to the user while producing a signature that does not cryptographically guarantee that the approved recipient remains unchanged. Critically, the flaw does not expose a user's private key.

Scope of the Fix

Bitcoin Core already rejected the edge case through its raw-transaction signing interface, but its PSBT path could still sign affected transactions. The new code moves the check into Bitcoin Core's shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed while allowing other valid inputs in the same PSBT to proceed.

PSBTs are commonly used to coordinate transactions between software wallets, hardware devices, and offline signers. They allow transaction builders to pass information to a separate signer without giving that system control of private keys.

Wallet Provider Responsibility

Users do not yet have access to a confirmed production release containing the safeguard. The change remains in Bitcoin Core's development branch as of early October, with no fixed version or confirmed backport identified. This leaves wallet providers and hardware-signing integrations with an immediate decision: review their own handling of SIGHASH_SINGLE requests rather than waiting for a Bitcoin Core release to enforce the same protection downstream.

Bitcoin Improvement Proposal 174, which defines PSBTs, already directs signers to reject unacceptable signing modes and recommends SIGHASH_ALL when no alternative is specified. The Bitcoin Core change explicitly prevents the missing-output configuration from reaching the signing stage.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $85,899.90+1.41% EthereumETH $2,705.61+0.72% Tether USDUSDT $1.00+0.02% BNBBNB $792.70+0.95% XRPXRP $1.51+1.51% USDCUSDC $1.00+0.02% SolanaSOL $121.21+1.32% TRONTRX $0.3358+0.18% HyperliquidHYPE $90.63+1.08% ZcashZEC $1,337.08+1.56%
Prices by Coinranking. Informational only.