Live Prices
Bitcoin

Bitcoin Core Fixes SIGHASH_SINGLE Vulnerability in PSBT Workflows

TheCryptoDesk Editorial · 2m read
Bitcoin Core Fixes SIGHASH_SINGLE Vulnerability in PSBT Workflows

Bitcoin Core developers have merged a safeguard into the master development branch to fix a vulnerability in partially signed Bitcoin transactions (PSBTs) that could allow funds to be redirected without compromising private keys. The update, merged on Sept. 25 and highlighted by Bitcoin Optech on Oct. 2, closes a flaw related to the SIGHASH_SINGLE signing flag.

Technical Details of the SIGHASH_SINGLE Flaw

The vulnerability occurs under specific edge cases involving the SIGHASH_SINGLE signing mode, which binds a transaction input to an output at the corresponding index position. If a transaction lacks an output at that matching index, the structural protection breaks down depending on the transaction input type.

For legacy inputs, a missing output results in a signature created over a fixed hash value, which could potentially be reused against other unspent transaction outputs controlled by the same private key under matching conditions. For SegWit v0 inputs, while the signature remains bound to the specific coin and amount being spent, the destination recipient output remains unbound. Consequently, software wallets could display an approved payment destination to a user while generating a signature that fails to cryptographically guarantee that recipient.

While Bitcoin Core previously blocked these edge cases within its raw-transaction signing interface, its PSBT execution path—including the walletprocesspsbt call—remained capable of signing them. The new fix shifts the restriction directly into Bitcoin Core's shared signature-creation logic, rejecting affected legacy and SegWit v0 inputs while allowing unaffected inputs in the same PSBT to proceed. As Bitcoin trades near key technical levels, maintaining protocol security and transaction integrity remains a primary focus for developers.

Implementation Across Wallets and Hardware Signers

The fix aligns directly with Bitcoin Improvement Proposal 174 (BIP 174), which dictates that PSBT signers should reject unacceptable signing modes and default to SIGHASH_ALL unless specified otherwise.

Key details surrounding the software patch include:

  • Sept. 25 merge date into Bitcoin Core’s master code repository.
  • Impact restricted to SIGHASH_SINGLE transactions lacking corresponding index outputs.
  • Prevention of fixed-hash signature reuse in legacy inputs and unbound recipient destinations in SegWit v0.
  • Inclusion of logic blocking affected inputs in the walletprocesspsbt workflow.
  • Absence of a confirmed production release or official backport as of Oct. 4.

Why It Matters

This code update reinforces crucial transaction-authorization boundaries between signing software, hardware wallets, and coordination systems. Because PSBTs are widely relied upon for multi-party signatures and cold storage setups, ensuring that a signature strictly binds funds to the user-approved destination is critical. Wallet developers and hardware manufacturers will likely need to review their own signature validation protocols ahead of an official Bitcoin Core client release.

Read next