Bitcoin Core adds safeguard against unsafe PSBT transaction signing

  • Bitcoin Core added a safeguard blocking risky PSBT signing requests.
  • Sept. 25 marked the safeguard’s merge into Bitcoin Core’s development branch.
  • Wallet providers must review SIGHASH_SINGLE handling pending a confirmed production release.

Bitcoin Core has added a safeguard against signing partially signed Bitcoin transactions, or PSBTs (files coordinating transaction signing), when the signature may not bind funds to the recipient approved by the user. The issue involves SIGHASH_SINGLE, a signing mode that normally links an input to the output in the same position. If that output is missing, legacy inputs can produce a signature over a fixed hash value, while SegWit v0 inputs retain commitment to the spent coin and amount but may leave the destination output unbound. The flaw does not reveal private keys, but could allow a valid signature to remain usable after a recipient is changed under specific conditions. The check was merged into Bitcoin Core’s master development branch on Sept. 25 and highlighted by Bitcoin Optech on Oct. 2. Bitcoin Core’s shared signature-creation logic now rejects affected legacy and SegWit v0 inputs while allowing other valid inputs in the same PSBT to proceed. As of Oct. 4, no confirmed production release or backport containing the safeguard had been identified, leaving wallet providers and hardware-signing integrations to review their own handling of SIGHASH_SINGLE requests.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.