Key Highlights:
- Bitcoin Core developers have addressed an authorization vulnerability involving the
SIGHASH_SINGLEsigning mode when a transaction lacks a corresponding output. - While legacy raw-transaction signing interfaces previously blocked this edge case, the Partially Signed Bitcoin Transaction (PSBT) workflow remained susceptible, potentially allowing signatures that fail to bind the approved recipient.
- Merged into Bitcoin Core’s development branch on September 25, the fix has not yet appeared in a tagged production release or confirmed backport as of October 4, shifting immediate review responsibilities to third-party wallet and hardware signing developers.
Understanding the SIGHASH_SINGLE Vulnerability in Bitcoin Core
Bitcoin Core developers have updated the project’s codebase to resolve a critical signature verification edge case tied to the SIGHASH_SINGLE signing flag. Under normal operations, SIGHASH_SINGLE is designed to bind a specific transaction input directly to the output situated at the matching index. However, when a transaction lacks an output at that designated position, the cryptographic commitment behaves unexpectedly, creating distinct vulnerabilities across different Bitcoin transaction formats.
For legacy transaction inputs, the absence of a corresponding output causes the system to generate a signature over a fixed hash value. Bitcoin Core developers warned that this behavior means an existing signature could potentially be reused against other unspent transaction outputs (UTXOs) controlled by the identical private key whenever matching structural conditions occur. In contrast, Segregated Witness (SegWit v0) transactions offer partial mitigation by committing to the specific coin and value being spent; nevertheless, the destination output can still remain uncommitted, leading to serious authorization discrepancies.
Risks Across Partially Signed Bitcoin Transactions (PSBT)
The core danger of this unbound signature state centers on authorization integrity within user-facing wallets and signing infrastructure. When signing software processes these requests, an interface might display an intended transaction destination to a user, yet generate a signature that fails to cryptographically bind the funds to that specified recipient.
Prior to the latest patch, Bitcoin Core successfully blocked this specific anomaly inside its raw-transaction signing interface. However, the workflow for Partially Signed Bitcoin Transactions (PSBT)—specifically within remote commands such as walletprocesspsbt—could still execute the vulnerable signature. Because PSBTs, specified by Bitcoin Improvement Proposal 174 (BIP 174), are standard for orchestrating transfers across software wallets, hardware devices, and air-gapped systems, ensuring uniform rejection logic across all processing pathways is critical to securing offloaded key signing.
Bitcoin Core Moves Safeguards to Shared Logic
To eliminate the discrepancy, the new patch moves validation checks directly into Bitcoin Core’s shared signature-creation subsystem. Under this unified implementation, the engine automatically prevents affected legacy and SegWit v0 inputs from executing the invalid SIGHASH_SINGLE signing process. Meanwhile, any valid inputs contained within the same PSBT package can continue through the signing process uninterrupted.
Although BIP 174 guidelines instruct signers to dismiss unacceptable signing configurations and urge developers to default to SIGHASH_ALL, the updated Bitcoin Core logic enforces programmatic enforcement, preventing missing-output transaction configurations from progressing to signature generation.
Why This Matters
This update reinforces an essential security tenet for cryptocurrency custody: private key isolation alone does not guarantee security if the signature generated does not explicitly bind to the exact terms approved by the user. The update was merged into the Bitcoin Core development branch on September 25, but published release listings showed no tagged production release or confirmed backport as of October 4.
Consequently, the immediate responsibility rests with external wallet maintainers, hardware wallet manufacturers, and custody platforms. These entities must audit their proprietary signing libraries and firmware to ensure they do not sign SIGHASH_SINGLE inputs lacking matching outputs, rather than waiting for downstream distribution of updated Bitcoin Core releases.
Frequently Asked Questions
What is the SIGHASH_SINGLE issue in Bitcoin Core?
The issue occurs when an input is signed using SIGHASH_SINGLE without a corresponding transaction output at the same index. In legacy transactions, this generates a signature over a fixed hash that could be replayed on matching inputs. In SegWit v0, it leaves the payment destination unbound by the signature, creating a potential authorization mismatch.
Were PSBT workflows affected differently than raw transactions?
Yes. Bitcoin Core’s raw-transaction signing interface previously caught and rejected this missing-output edge case. However, its PSBT interface—including functions like walletprocesspsbt—did not consistently block it, allowing affected signatures to be produced during multi-step or hardware wallet signing routines.
Is this fix currently available in a general Bitcoin Core release?
As of October 4, the fix has been merged into Bitcoin Core’s development branch following its September 25 integration, but it has not yet been designated in an official production software release or confirmed backport.




