BIP461 Catches Hidden Key Leaks. It Just Won't Prove Them.
A new draft Bitcoin improvement proposal, BIP461, wants every compliant ECDSA signer to produce byte-for-byte identical signatures. That gives auditors a benchmark for spotting deviations, and deviations are where leaked private keys hide. It's detection, not proof, and that distinction matters.
In August 2013, a bad random number generator in Android started draining Bitcoin wallets. Not through brute force. Through nonces. Every signature leaked a little piece of the private key, and nobody could see it happening.
Twelve years later, a draft proposal wants to make that kind of silent leak a lot harder to hide.
What BIP461 Actually Does
Bitcoin improvement proposal BIP461, authored by Liam Gilligan, defines a common signing procedure for ECDSA, the signature scheme Bitcoin has used since the genesis block. Here's the thing: if two independent, compliant signers get the same secret key and the same message hash, they should produce identical signatures. Byte for byte.
That's the whole trick. It's a benchmark.
ECDSA on secp256k1 burns a 32-byte nonce for every signature. Reuse one, or generate it weakly, and the private key falls out with simple algebra. Any device that picks its nonces sloppily is a key leak waiting to happen. And you can't tell by looking at the wallet, the firmware, or the vendor's whitepaper.
Now you can compare. Once a deterministic baseline exists, signatures that deviate from it get flagged. A deviation isn't proof of anything. It's a signal that something in the signing stack isn't behaving like everyone else. Could be a bug. Could be a strange optimization. Could be firmware quietly bleeding key material one signature at a time.
The proposal doesn't claim to catch malicious firmware. It catches the fingerprints malicious firmware would leave behind.
Detection Isn't Proof, and That's Fine
Real talk: this industry keeps hunting for a silver bullet against supply chain attacks. There isn't one. Hardware wallets, air-gapped signers, multisig, all of it raises the cost of an attack. None of it removes the trust you place in the silicon.
BIP461 doesn't change that math. What it does is hand auditors, wallet devs, and paranoid degens a cheap way to notice when a device stops coloring inside the lines.
That's a big deal commercially. A hardware vendor that can't show clean, reproducible signatures has a problem on its hands. A vendor that can prove determinism under a published procedure has a sales pitch. Whales sitting on nine figures of cold storage care about this more than they care about another L2.
But let's be honest about the limits. Reproducibility only works if the compliant spec is actually followed. If two firmware builds deviate in the same coordinated direction, the benchmark drifts with them. You need honest implementations to anchor the reference. That's a governance problem, not a math problem.
Is that a reason to skip it? No. It's a reason to stop treating detection as a finish line.
What to Watch
The chain doesn't lie, but firmware can. BIP461 is an early draft. It's not merged, not activated, and not something you should price into your next cold storage decision today. The draft is a draft.
What matters is whether signer implementations adopt it and publish their test vectors. Watch for wallet vendors volunteering to reproduce signatures against a public reference. The ones that do are telling you something. The ones that stay quiet are telling you something too.
Look, determinism in signing isn't a nice-to-have. It's the only way to tell whether your device does what it says on the box. Anon, let me explain one last thing: the fix isn't stronger hardware. It's making the boring part observable.