Bitcoin Core’s new fix closes gap that could redirect funds without stealing keys

3 hours ago 3



Bitcoin Core has added a safeguard against signing transactions that may not bind funds to the payment destination a user approved.The change, merged into Bitcoin Core’s master development branch on Sept. 25, targets a narrow flaw in partially signed Bitcoin transactions, or PSBTs, that could produce a valid signature without protecting the intended output.Bitcoin Optech highlighted the update on Oct. 2. The issue does not expose a user’s private key, but creates a different risk: a signature can remain valid even when the transaction’s recipient is changed under specific conditions.The weakness involves SIGHASH_SINGLEwhich is a signing mode designed to commit an input to the output in the corresponding position. If the transaction contains no output at that position, the protection breaks down differently depending on the type of Bitcoin being spent.For legacy inputs, the missing-output case can produce a signature over a fixed hash value. Bitcoin Core developers said that signature may then be reusable against other unspent outputs controlled by the same key when the same structural conditions are present.SegWit v0 transactions retain stronger protections because the signature st...

Read Entire Article