Bitcoin Core has implemented a protective measure to prevent the signing of transactions where funds might be redirected without the spender’s explicit approval.
The update, integrated into Bitcoin Core’s main development branch on Sept. 25, addresses a limited risk in Partially Signed Bitcoin Transactions (PSBTs) that previously allowed for valid signatures to be generated without securing the intended payment output.
The development was highlighted by Bitcoin Optech on Oct. 2. While the vulnerability doesn’t compromise private keys directly, it introduces another concern: under certain conditions, a signature could still be considered valid even if the transaction’s recipient is altered without authorization.
The flaw pertains to SIGHASH_SINGLE, a signature hashing method intended to tie an input to its corresponding output. However, in cases where no matching output exists at the expected position, the safeguard fails in ways that vary based on the type of Bitcoin being spent.
In legacy input scenarios, the missing output situation can lead to signatures over a constant hash value. According to Bitcoin Core developers, such signatures could potentially be repurposed against other unspent outputs governed by the same key, provided similar structural criteria are met.
For SegWit v0 transactions, protections remain stronger since the signature continues to bind to the specific UTXO being spent along with its associated amount. Nevertheless, the destination output might still lack binding in some cases.
This creates a security concern for wallets and signing devices: applications might show one payment to users while generating a signature that doesn’t cryptographically enforce that the recipient stays unchanged from what was authorized.
Bitcoin Core Blocks High-Risk Signing Requests
Previously, Bitcoin Core already declined such edge-case situations via raw transaction signing methods. Its PSBT handling—including functions like walletprocesspsbt—remained susceptible.
The latest modification integrates the safeguard into Bitcoin Core’s shared signature-creation framework, disallowing affected legacy and SegWit v0 inputs from undergoing the signing process while permitting unaffected inputs within the same PSBT to proceed normally.
As PSBTs play a central role in coordinating cross-application transactions—including interactions between full-node software, hardware wallets, and air-gapped signers—ensuring robust enforcement at this layer becomes critical.
Consequently, the fix strengthens a key boundary that wallet developers must independently validate: ensuring that cryptographic signatures align with the actual transaction parameters approved by the user.
Furthermore, Bitcoin Improvement Proposal 174—which outlines PSBT standards—urges signers to reject inappropriate signature modes and suggests using SIGHASH_ALL when alternatives aren’t necessary. This patch codifies those recommendations by actively preventing problematic configurations from reaching the signing phase.
Major Bitcoin Core update changes default wallet protocols, risking temporary disruption across popular apps
At present, no official production release includes the mitigation. The Sept. 25 integration resides solely within Bitcoin Core’s active development track, and as of Oct. 4, neither a targeted release nor confirmed backport schedule had been announced publicly.
This places greater responsibility on wallet vendors and hardware-signing ecosystems to assess their own management of SIGHASH_SINGLE operations ahead of broader adoption downstream through Bitcoin Core distributions.


