A vulnerability has been identified concerning SIGHASH_SINGLE, a signing mode that intends to link an input to a specific output position. When a transaction lacks an output at that designated spot, the existing safeguard degrades, which varies based on the Bitcoin type being utilized.

For traditional inputs, the absence of an output can create a signature based on a static hash value. Developers of Bitcoin Core have pointed out that such a signature might be reused for other unspent outputs linked to the same private key under similar structural conditions.

In contrast, SegWit v0 transactions offer enhanced security, as the signature still refers to the precise coin being utilized and its amount. Nonetheless, the destination output remains flexible.

This situation leads to a challenge for wallets and signing devices: software might display one payment option to the user while generating a signature that fails to securely verify that the authorized recipient has not changed.

Bitcoin Core Stops Potentially Dangerous Signing Requests

Bitcoin Core has already blocked this edge case through its raw transaction signing interface. However, its PSBT method, particularly walletprocesspsbt, is still capable of signing it.

The newly implemented code shifts the verification process into the shared signature-creation framework of Bitcoin Core, thus preventing the signing of vulnerable legacy and SegWit v0 inputs while still allowing valid inputs within the same PSBT.

Partially Signed Bitcoin Transactions (PSBTs) are frequently utilized to facilitate collaborations between software wallets, hardware devices, and offline signers. They enable transaction creators to relay information to an independent signer without relinquishing control of private keys.

This enhancement solidifies a boundary that wallet developers must uphold independently of key security: any valid cryptographic signature must be tied to the transaction specifics that the user has actually approved.

Bitcoin Improvement Proposal 174, which defines PSBTs, already instructs signers to dismiss improper signing modes and advocates for using SIGHASH_ALL when no other option is specified. The revision in Bitcoin Core specifically prevents this missing-output scenario from advancing to the signing phase.

As of now, users have not received a confirmed production release that includes this safeguard. The update, finalized on September 25, has been integrated into Bitcoin Core’s development branch, but the published release notes have not yet indicated a fixed version or confirmed backport as of October 4.

This situation prompts wallet providers and hardware-signing integrations to promptly assess their own management of SIGHASH_SINGLE requests, rather than waiting for a Bitcoin Core release to implement the same protective measures downstream.

Share.