Bitcoin Core Adds Safeguard Against Malicious Transaction Signatures
Bitcoin Core has implemented a safeguard against signing transactions that may not bind funds to the intended payment destination. The change, merged into Bitcoin Core's master development branch on September 25, targets a narrow flaw in partially signed Bitcoin transactions (PSBTs) that could produce a valid signature without protecting the recipient.
The issue does not expose users' private keys but creates a risk: a signature can remain valid even when the transaction's recipient is changed under specific conditions. The weakness involves SIGHASH_SINGLE, a signing mode designed to commit an input to the output in the corresponding position.
Bitcoin Core developers have moved the check into their shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed while allowing other valid inputs in the same PSBT to proceed. This fix reinforces a boundary that wallet developers must enforce independently of key security: a valid cryptographic signature must commit to the transaction details the user actually authorized.
Users do not yet have a confirmed production release containing the safeguard, but wallet providers and hardware-signing integrations are advised to review their handling of SIGHASH_SINGLE requests rather than waiting for a Bitcoin Core release to enforce the same protection downstream.