Bitcoin Core Patch Blocks Risky Signing Requests for Partially Signed Transactions
A recent update to Bitcoin Core has patched a vulnerability that could allow funds to be redirected without stealing a user's private key. The issue, which affects partially signed Bitcoin transactions (PSBTs), was identified as a narrow flaw that could produce a valid signature without protecting the intended output.
The problem arises when using the SIGHASH_SINGLE signing mode, which is designed to commit an input to the corresponding output. However, if the transaction contains no output at that position, the protection breaks down differently depending on the type of Bitcoin being spent.
Bitcoin Core developers have noted that this weakness involves a signature that may be reusable against other unspent outputs controlled by the same key when the same structural conditions are present. The destination output can remain unbound, creating an authorization problem for wallets and signing devices.
The update, merged into Bitcoin Core's master development branch on September 25, moves the check into Bitcoin Core's shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed. Users do not yet have a confirmed production release containing the safeguard.