Bitcoin Core blocks PSBT case that could redirect funds

A Sept. 25 update merged into Bitcoin Core’s master branch prevents a PSBT edge case where SIGHASH_SINGLE signatures could remain valid after a recipient is changed. Wallets should review signing logic.

Bitcoin Core merged a change into its master development branch on Sept. 25 that prevents a narrow partially signed Bitcoin transaction (PSBT) case in which SIGHASH_SINGLE signatures could remain valid after the intended recipient is changed. The update affects certain legacy and SegWit v0 inputs and stops those inputs from being signed under a missing-output condition.

SIGHASH_SINGLE is a signing mode meant to link an input to the output at the same index. If a transaction lacks an output at that index, protections differ by input type. For legacy inputs, the missing-output case can yield a signature over a fixed hash value; developers warned such a signature might be replayable against other unspent outputs controlled by the same key when the transaction structure meets specific conditions. For SegWit v0 inputs, signatures continue to commit to the spent coin and its amount, but they may not cryptographically bind the approved destination, allowing a recipient to be substituted in narrow scenarios.

The issue does not expose private keys. Instead, it creates an authorization gap: software or hardware signers could display one payment to a user while producing a signature that does not guarantee the recipient remains the same. PSBTs are used to coordinate transactions between transaction builders, software wallets, hardware devices and offline signers; the format separates construction from signing and depends on signers enforcing which signing modes they accept.

Before the change, Bitcoin Core’s raw-transaction signing path rejected the edge case, but the PSBT signing flow could still reach the vulnerable logic. The merged update moves the check into the shared signature-creation code so affected legacy and SegWit v0 inputs are blocked from being signed while other valid inputs in the same PSBT can still proceed.

Bitcoin Improvement Proposal 174, which defines PSBT behavior, tells signers to reject unacceptable signing modes and recommends SIGHASH_ALL when no stronger option exists. The recent code change prevents the missing-output configuration from reaching the signing stage, enforcing that a produced signature must commit to the transaction details the signer presented to the user.

As of early October, the safeguard exists only in Bitcoin Core’s master development branch and is not yet in a confirmed production release or listed for backport. Wallet developers and hardware-signing integrations are advised to inspect and, if needed, update their handling of SIGHASH_SINGLE requests rather than waiting for a released Bitcoin Core version. Users should monitor wallet and device vendors for updates and advisories.

Articles by this author