Bitcoin Core Patch Blocks 'Redirect Funds' Vulnerability
A recent update to Bitcoin Core has patched a vulnerability in partially signed Bitcoin transactions (PSBTs) that could have allowed funds to be redirected without stealing users' private keys.
The issue, which was identified as a narrow flaw in the signing process, involved SIGHASH_SINGLE, a signing mode designed to commit an input to the output in the corresponding position. If the transaction contained no output at that position, the protection broke down differently depending on the type of Bitcoin being spent.
The vulnerability did not expose users' private keys but created another risk: a signature could remain valid even when the transaction's recipient was changed under specific conditions. This created an authorization problem for wallets and signing devices, as software could present one payment to the user while producing a signature that did not cryptographically guarantee the approved recipient remained unchanged.
The new code moves the check into Bitcoin Core's shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed. This change was merged into Bitcoin Core's development branch on September 25 and has yet to be included in a confirmed production release.