Bitcoin Core Patch Closes Vulnerability in PSBTs
Bitcoin Core has implemented a security fix to prevent a potential vulnerability in partially signed Bitcoin transactions (PSBTs). The change, merged into the master development branch on September 25, addresses a flaw in the SIGHASH_SINGLE signing mode that could allow a signature to remain valid even if the recipient's output is changed.
The issue does not expose a user's private key, but creates a risk that a signature can be reused against other unspent outputs controlled by the same key under specific conditions.
Bitcoin Optech highlighted the update on October 2, noting that the vulnerability is limited to legacy inputs and SegWit v0 transactions, which retain stronger protections. However, the destination output can remain unbound, creating an authorization problem for wallets and signing devices.
The new code moves the check into Bitcoin Core's shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed while allowing other valid inputs in the same PSBT to proceed.
The fix reinforces a boundary that wallet developers must enforce independently of key security: a valid cryptographic signature must commit to the transaction details the user actually authorized.