Bitcoin Upgrade Seeks to Prevent Hidden Key Leaks
A new Bitcoin upgrade, known as BIP461, aims to prevent hidden key leaks in wallet secrets. The proposal, authored by Liam Gilligan, defines a common signing procedure for ECDSA, an existing Bitcoin signature scheme.
This standardized process ensures that independent compliant signers produce identical signatures for the same secret key and message hash, creating a benchmark for detecting potential key leakage.
The draft has been merged into the BIPs repository and remains marked as Draft. It works under existing Bitcoin consensus rules, requiring no consensus change to implement.
ECDSA allows signers to make choices while creating valid signatures, which can be exploited by malicious firmware to hide key material in signatures that still pass verification. BIP461 fixes these choices through a specified deterministic procedure, comparing signatures for deviations and keeping them to at most 70 bytes in the standard DER encoding.