A new Bitcoin Improvement Proposal, BIP461, aims to make hidden pathways used for leaking wallet secrets easier to detect. Authored by Liam Gilligan, the proposal was merged into the official BIPs repository on Sept. 16 as a Draft and operates under existing consensus rules without requiring a network soft or hard fork.
Deterministic Signing to Expose Malicious Firmware
Under Bitcoin's legacy ECDSA signature scheme, signers have choices when generating valid transaction signatures, particularly in selecting the nonce—a temporary cryptographic value. Malicious hardware or corrupted firmware can exploit this flexibility to covertly embed seed phrases and private key material inside signatures that pass standard verification checks.
BIP461 addresses this vulnerability by specifying a standardized, deterministic signing procedure. By establishing an exact output benchmark, signers using identical secret keys and message hashes should produce identical signatures. Any variance between independent compliant signers alerts users that at least one device is deviating from the protocol standard. Additionally, the algorithm restricts signature lengths to a maximum of 70 bytes in standard DER encoding, excluding Bitcoin's one-byte sighash flag.
Dark Skippy Context and Implementation Constraints
The proposal follows the Dark Skippy security disclosure, which demonstrated how compromised firmware can exfiltrate secret seed data via transaction signatures. While Dark Skippy focused on Schnorr signatures used in Taproot (BIP340), BIP461 targets ECDSA signatures specifically and does not directly remedy Schnorr-based implementations.
Detecting discrepancies using BIP461 requires executing identical inputs on a second independent signer with access to the same private key, which introduces secondary key exposure risks. Furthermore, researchers caution that compromised firmware could selectively generate compliant signatures during testing while leaking data only on specific live transactions. At the time of its Sept. 16 merge, a protocol reviewer noted that BIP461 requires test vectors and a reference implementation before moving to Complete status, as developers continue working on infrastructure amid ongoing shifts in Bitcoin market dynamics.
Key Takeaways
- BIP461 was merged as a Draft on Sept. 16 by author Liam Gilligan with no consensus changes needed.
- Fixes ECDSA nonce selection choices to cap signature sizes at 70 bytes in DER encoding (plus a 1-byte sighash flag).
- Benchmark comparison requires exposing private keys to an independent second signer, providing a single-sample test rather than a full guarantee.
- Moving to Complete status requires dedicated test vectors and a reference implementation.
Why It Matters
As hardware wallet security faces increasingly sophisticated firmware-level exploits like Dark Skippy, deterministic signing benchmarks provide a vital verification layer for enterprise custodians and individual self-custody users. While BIP461 does not offer a standalone, automatic detection system, establishing rigid output standards allows security auditors to build reliable automated test environments. Wallet hardware providers will likely face growing pressure to adopt standardized ECDSA and Schnorr signing benchmarks to guarantee user funds remain protected against covert exfiltration.



