Sunday, October 4, 2026

Latest Posts

Bitcoin Core’s new fix closes gap that could redirect funds without stealing keys

Bitcoin Core has added a safeguard against signing transactions that may not bind funds to the payment destination a user approved.

The change, merged into Bitcoin Core’s master development branch on Sept. 25, targets a narrow flaw in partially signed Bitcoin transactions, or PSBTs, that could produce a valid signature without protecting the intended output.

Bitcoin Optech highlighted the update on Oct. 2. The issue does not expose a user’s private key, but creates a different risk: a signature can remain valid even when the transaction’s recipient is changed under specific conditions.

The weakness involves SIGHASH_SINGLEwhich is a signing mode designed to commit an input to the output in the corresponding position. If the transaction contains no output at that position, the protection breaks down differently depending on the type of Bitcoin being spent.

For legacy inputs, the missing-output case can produce a signature over a fixed hash value. Bitcoin Core developers said that signature may then be reusable against other unspent outputs controlled by the same key when the same structural conditions are present.

Read More:  Sudden 22% XRP rally triggers forced market wide short-buying, driving XRP toward a make-or-break resistance test

SegWit v0 transactions retain stronger protections because the signature still commits to the specific coin being spent and its amount. The destination output, however, can remain unbound.