Bitcoin Core’s new fix closes gap that could redirect funds without stealing keys

Bitcoin Core’s new fix closes gap that could redirect funds without stealing keys

Summary

Bitcoin Core merged a safeguard into its development branch to block a narrow PSBT signing flaw involving SIGHASH_SINGLE. Under specific conditions, affected signatures could fail to bind a transaction to the recipient shown to the user, without exposing private keys. The issue affected legacy and SegWit v0 inputs when the corresponding output was missing; Bitcoin Core’s raw-transaction interface already rejected the case, but its PSBT signing path did not. The shared signing logic now rejects affected inputs while allowing other valid inputs in the same PSBT to proceed. No production release containing the fix had been confirmed as of Oct. 4, so wallet and hardware-signing providers should review their handling of these requests.