Bitcoin Core Adds Safeguard Against Payment Signing Flaw
Bitcoin Core merged a safeguard on September 25, 2026 that prevents its signing code from producing a detached signature on SIGHASH_SINGLE inputs that have no c...
Bitcoin Core merged a safeguard on September 25, 2026 that prevents its signing code from producing a detached signature on SIGHASH_SINGLE inputs that have no corresponding output, closing a gap that could allow a payment’s recipient to be changed without exposing the owner’s private key.
What the Bitcoin Core signing flaw could change
SIGHASH_SINGLE is designed to commit a transaction input to the output at the same index, binding the signature to one specific destination. When that matching output is absent, the binding breaks: legacy signing hashes a fixed value of 1 and SegWit v0 leaves hashOutputs zeroed, so the resulting signature does not commit to any recipient at all. For related coverage, see VanEck BNB ETF Adds Staking Objective.
The practical consequence is severe. A signature produced under that edge case stays valid even after outputs are swapped, because the signing digest never captured the destination in the first place. Per Bitcoin Optech, legacy inputs are at additional risk: a missing-output SIGHASH_SINGLE signature can be reused against other UTXOs controlled by the same key so long as the missing-output condition remains. For related coverage, see Bitcoin Falls Below $84K as Crypto Liquidations Near $600M.
Why the flaw is a footgun, not a theft-of-keys attack
Contributor Matias Furszyfer (furszy), who authored the fix, wrote in the pull request: “SIGHASH_SINGLE only commits to the output at the input’s index. If the output at such position doesn’t exist, it commits to no output at all … which means the signature stays valid even when outputs are swapped, which is a footgun that lets funds be redirected without the owner’s consent.”
No private key needs to be extracted. The attacker works entirely with a legitimately produced but incorrectly scoped signature, making the attack difficult to detect through key-hygiene checks alone. Bitcoin currently trades near $85,400, giving the flaw real monetary stakes even for modest UTXO sets.
How Bitcoin Core’s new safeguard addresses the risk
PR #35984 moves the missing-output check into CreateSig, the shared signing primitive. Because SignTransaction, SignPSBTInput, and any future signing path all call through CreateSig, none of them will produce the dangerous signature going forward. Crucially, other valid inputs in the same PSBT are unaffected and continue to be signed normally.
Before the patch, SignTransaction already sidestepped the edge case but SignPSBTInput, and therefore walletprocesspsbt, could still sign it. That asymmetry meant wallet flows relying on PSBT (BIP174) for offline or hardware signing were exposed while direct signing appeared safe. The consolidation into CreateSig eliminates the divergence.
Operational security takeaway for node and wallet operators
The fix does not silently produce a wrong signature; it refuses to sign the affected input entirely. Operators using walletprocesspsbt will see those inputs skipped rather than receiving a malleable authorization. The Bitcoin Q4 outlook remains shaped by macro factors, but wallet-level hygiene now has one fewer hidden failure mode to account for.
What users and developers should watch next
As of October 4, 2026, the safeguard is on Bitcoin Core’s development master branch. No tagged production release or confirmed backport schedule had been identified at time of writing, per CryptoSlate‘s rollout coverage. Downstream wallet software and hardware signers that implement their own PSBT signing logic will require separate reviews to determine whether they are independently affected.
No CVE identifier had been assigned and no definitive list of affected wallet-provider versions was available in the disclosed materials. Users should monitor official Bitcoin Core release notes for the version that incorporates PR #35984 before drawing operational conclusions. Bitcoin’s recent push past the $85K sell wall signals continued on-chain activity, making timely adoption of the signing safeguard a practical priority for custodial and non-custodial wallet maintainers alike.
The Bitcoin and Ethereum ETF weekly flow picture also underscores growing institutional exposure to Bitcoin, raising the operational stakes for any signing-layer vulnerability that could redirect funds at the wallet level.
TLDR keypoints
- Bitcoin Core PR #35984, merged September 25, 2026, prevents signing of SIGHASH_SINGLE inputs that lack a corresponding output, stopping production of signatures that do not commit to a payment recipient.
- The check is now in
CreateSig, coveringSignTransaction,SignPSBTInput, and future signing paths; other valid PSBT inputs are unaffected. - The fix is on the development branch only; no production release version or confirmed backport has been announced, and downstream wallet implementations require separate review.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
More From Crypto News
Coinbase Makes ‘It’s So Over’ and ‘We’re So Back’ Predictions Tradeable
Coinbase has announced a way to trade on crypto’s two most recognizable mood swings, turning the viral phrases “It’s so over” and “we’re so back” into actual pr...
Bitcoin Falls Below $84K as $360M Longs Liquidate
Bitcoin fell below $84,000 as approximately $360 million in crypto long positions were forcibly closed in a single 10-minute window, marking one of the sharper...
Bloomberg Terminal Adds Real-Time Hyperliquid Prices
Bloomberg Terminal has begun displaying Hyperliquid prices in real time, according to a post shared on X by crypto exchange Bitso, marking a new visibility mile...
FNB South Africa Launches Crypto Trading for 9M Customers
South Africa’s First National Bank has announced the launch of crypto trading services for its retail customer base, a move that could extend digital-asset acce...
CFTC Seeks Clearer U.S. Rules for Leveraged Crypto Trading
Leveraged crypto trading allows participants to control positions larger than their deposited capital, amplifying both gains and losses. In the U.
$67.4M in Pendle AUSD Principal Tokens on Aave Monad Mature Oct. 8
About 67. 4 million PT-AUSD-8OCT2026 tokens were supplied as collateral on Aave V3’s Monad market as of Oct.
Author
Akita Inu
Akita Inu covers fast-moving crypto market updates, exchange news, and token ecosystem developments for CoinLive, with a focus on concise source-led reporting.