Bitcoin Core Safeguards Against Invalid Transaction Signatures
Bitcoin Core has added a safeguard to prevent signing transactions that may not bind funds to the intended payment destination. This change targets a narrow flaw in partially signed Bitcoin transactions, or PSBTs, that could produce a valid signature without protecting the recipient.
The issue involves SIGHASH_SINGLE, a signing mode designed to commit an input to the output in the corresponding position. If the transaction contains no output at that position, the protection breaks down differently depending on the type of Bitcoin being spent.
Bitcoin Core developers have moved the check into their shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed while allowing other valid inputs in the same PSBT to proceed. This change reinforces a boundary that wallet developers must enforce independently of key security: a valid cryptographic signature must commit to the transaction details the user actually authorized.
The fix is currently only available in Bitcoin Core's development branch, leaving wallet providers and hardware-signing integrations with the decision to review their own handling of SIGHASH_SINGLE requests rather than waiting for a Bitcoin Core release to enforce the same protection downstream.