Bitcoin Core Patches Flaw Allowing Funds to Be Redirected Without Stealing Keys
Bitcoin Core has added a safeguard against signing transactions that may not bind funds to the payment destination a user approved.
KuCoin
Publisher
Oct 4, 2026 at 7:52 PM UTC · Updated há um dia · 2 min de leitura

Key Signal
Sept. 25 Fix merged to branch
Entities
bitcoin
Last Updated
há um dia
Bitcoin Core has added a safeguard against signing transactions that may not bind funds to the payment destination a user approved.
The change, merged into Bitcoin Core’s master development branch on Sept. 25, targets a narrow flaw in partially signed Bitcoin transactions, or PSBTs, that could produce a valid signature without protecting the intended output.
Bitcoin Optech highlighted the update on Oct. 2. The issue does not expose a user’s private key, but creates a different risk: a signature can remain valid even when the transaction’s recipient is changed under specific conditions.
The weakness involves SIGHASH_SINGLEwhich is a signing mode designed to commit an input to the output in the corresponding position. If the transaction contains no output at that position, the protection breaks down differently depending on the type of Bitcoin being spent.
For legacy inputs, the missing-output case can produce a signature over a fixed hash value. Bitcoin Core developers said that signature may then be reusable against other unspent outputs controlled by the same key when the same structural conditions are present.
SegWit v0 transactions retain stronger protections because the signature still commits to the specific coin being spent and its amount. The destination output, however, can remain unbound.
Market Context
Bitcoin
BTC
$85,800
-0.02% (24H)
Market Cap
$1.72T
24H Volume
$26.4B
24H High
$86,974
Article Intelligence
Key Entities
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
