Bitcoin Core Patched a Signing Flaw on Sept. 25. Most Wallets Still Ship Without the Fix.
Bitcoin Core merged a safeguard on Sept. 25 that blocks a narrow signing mode from producing signatures that don't bind funds to the recipient a user approved. The keys stay safe. The coins might not. And as of Oct. 4, no production release carries the fix, which leaves wallet developers holding the bag.
Bitcoin Core merged a fix on Sept. 25 for a signing flaw that never touches your private keys. The keys stay safe. The coins don't. That distinction matters more than most people want to admit.
The change targets SIGHASH_SINGLE, one of the oldest signing modes in Bitcoin, and it closes an edge case where a valid signature could survive even when the transaction's recipient gets changed under specific conditions. Bitcoin Optech flagged the update on Oct. 2. No production release contained the safeguard as of Oct. 4. Remember that date. It's the part of this story that actually matters.
What Actually Broke
SIGHASH_SINGLE does one job. It commits an input to the output sitting in the same position. Input zero to output zero, input one to output one, and so on down the line. If there's no output at that position, the commitment falls apart, and it falls apart differently depending on what type of bitcoin you're spending.
With legacy inputs, the missing-output case produces a signature over a fixed hash value. Developers describe that signature as potentially reusable against other unspent outputs controlled by the same key when the same structural conditions show up. With SegWit v0 inputs, which arrived in the August 2017 upgrade, you get better protection because the signature still commits to the specific coin and its amount. The destination output, though, can stay unbound.
The better analogy is a check with the amount filled in and the payee line left blank. The bank verifies the signature is real. It just doesn't verify who gets paid.
That's an authorization problem, not a key problem. A wallet or hardware signer could display one payment to you while producing a signature that makes no cryptographic promise the approved recipient stays the approved recipient.
Where the Gap Hid
Here's the strange part. Bitcoin Core's raw transaction signing interface already rejected the configuration. The PSBT path, including the walletprocesspsbt command, could still sign it.
PSBTs are how wallets, hardware devices, and offline signers coordinate transactions without handing over private keys. They're the plumbing behind most multisig setups and a lot of cold storage. Bitcoin Improvement Proposal 174, which defines the format, already tells signers to reject unacceptable signing modes and recommends SIGHASH_ALL when no alternative is specified. The recommendation existed. The enforcement didn't.
The Sept. 25 merge moves the check into Bitcoin Core's shared signature-creation logic. Affected legacy and SegWit v0 inputs get skipped. Every other valid input in the same PSBT proceeds normally. That's a clean fix to a messy problem, and it deserves credit for being boring.
The Counterpoint
Now steelman the other side, because the other side has a real argument.
This is narrow. Genuinely narrow. You need a missing output at a specific position, you need legacy or SegWit v0 inputs, and you need a key that controls other UTXOs with matching structure. Most modern wallets default to SIGHASH_ALL, which commits to every input and every output in the transaction. If your wallet doesn't offer SIGHASH_SINGLE as an option, this bug can't reach you.
And the fix lives in master, which is the development branch. Master isn't what's running on your node, your hardware wallet, or your favorite mobile app. Backports weren't confirmed as of Oct. 4. So the population actually exposed right now is small. Very small. Possibly zero in practice.
So who cares?
Pull the lens back far enough and the pattern emerges. The count of people currently at risk is the wrong number to count, and it's been the wrong number to count for a decade.
My Verdict
I'll commit. This fix matters, and not because of how many people it saves today.
Every major disaster in this industry has taught the same lesson twice. Mt. Gox lost roughly 850,000 bitcoin through operational failure, not broken cryptography. Hardware wallet phishing campaigns have drained users without cracking a single private key. This is a story about money. It's always a story about money. And money moves when someone authorizes it, which means authorization, not key security, has always been the real border.
People hear "your keys, your coins" and treat it as a law of physics. It's true about custody. It's false about signing. Cryptography guarantees a signature is authentic. It makes no promise the signature says what you think it says. That gap is the entire attack surface, and it's where the interesting failures keep happening.
The other thing worth sitting with: SIGHASH flags are original Bitcoin code. Satoshi wrote them. We're 17 years into this experiment and the protocol is still getting patched for a commitment quirk in a signing mode that almost nobody uses on purpose. That's not a scandal. That's maintenance, and maintenance is what keeps a 17-year-old network alive. To enjoy crypto, you'll have to enjoy failure too, because the failures are the curriculum.
So here's the concrete take, and it's aimed at developers rather than traders. The Bitcoin Core fix is a floor, not a ceiling. Wallet teams should audit their own PSBT handling this week rather than waiting for a release to arrive and save them. Refuse SIGHASH_SINGLE if you don't have a real reason to support it. Default to SIGHASH_ALL. Hardware signer manufacturers should display the full output commitment, not just the destination address, because the address is precisely the thing the signature may not be binding to.
The proof of concept is the survival. Bitcoin has survived every one of these patches, and each one makes the same quiet point. A protocol is only as strong as the weakest signing path that somebody's wallet actually uses. Go check yours.
Explore More
Key Terms Explained
The first cryptocurrency, created in 2009 by the pseudonymous Satoshi Nakamoto.
Who holds and controls your crypto assets.
A physical device that stores cryptocurrency private keys offline.
An Ethereum Layer 2 in the Optimism Superchain ecosystem that incentivizes developers and users through its referral and fee-sharing system.