Bitcoin Core Merges PSBT SIGHASH_SINGLE Fix to Close Fund-Redirection Risk

1 hour ago 2 sources positive

Key takeaways:

  • BTC wallets using PSBTs face unpatched signing risks, urging hardware vendors to audit SIGHASH_SINGLE handling.
  • This vulnerability highlights custody isn't enough; transaction-construction flaws can redirect BTC without private-key compromise.
  • Watch wallet backports before trading; unresolved PSBT risk may weigh on institutional BTC custody sentiment.

Bitcoin Core has merged a safeguard into its master development branch to address a narrow but serious transaction-signing vulnerability involving partially signed Bitcoin transactions, or PSBTs. The flaw affects the SIGHASH_SINGLE signing mode and could allow a signature to remain valid even if the payment destination is changed, without an attacker ever obtaining the user's private key.

The change was merged on Sept. 25 and highlighted by Bitcoin Optech on Oct. 2. The risk appears when a PSBT contains no output at the position corresponding to the input being signed. With legacy inputs, this missing-output case can produce a signature over a fixed hash value, which may then be reusable against other unspent outputs controlled by the same key under matching structural conditions. SegWit v0 inputs retain stronger protections because the signature commits to the specific coin being spent and its amount, but the destination output can remain unbound, creating an authorization gap between what a wallet displays and what the signature actually guarantees.

Bitcoin Core already rejected this edge case in its raw-transaction signing interface, but the PSBT path, including walletprocesspsbt, could still sign the risky configuration. The new code moves the check into shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed while allowing other valid inputs in the same PSBT to proceed. Bitcoin Improvement Proposal 174, which defines PSBTs, already advises signers to reject unacceptable signing modes and recommends SIGHASH_ALL when no alternative is specified.

As of Oct. 4, no confirmed production release containing the safeguard had been identified, and backports were not confirmed. Wallet providers and hardware-signing integrations may therefore need to review their own handling of SIGHASH_SINGLE requests rather than waiting for a downstream Bitcoin Core release. The issue underscores a distinct threat model from private-key compromise: a redirection gap can manipulate transaction destinations without key access, so key custody alone is not sufficient if transaction-construction software contains a flaw. Users and node operators are advised to follow official Bitcoin Core release guidance and apply the patch once available.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.