Bitcoin Core developers have merged a fix for a vulnerability in the SIGHASH_SINGLE request mechanism that could allow for the unauthorized redirection of funds without compromising private keys. The patch targets a scenario in which a missing-output SIGHASH_SINGLE request leaves recipients unbound, severing the cryptographic link between a signature and its intended destination while allowing the transaction to retain a valid appearance.

According to a report from CryptoSlate, the vulnerability arises during Partially Signed Bitcoin Transaction (PSBT) handling. SIGHASH_SINGLE is a signature hash type designed to commit a signer to a specific input and its matching output, ensuring that tampering with either would invalidate the signature. When an output is missing from the signing request, however, the mechanism does not bind the recipient, creating an avenue through which funds could be rerouted by an attacker who does not possess the victim’s private keys. Because the attack sidesteps the need for key theft entirely, it represents a different category of risk than conventional compromise vectors.

The merged repair updates Bitcoin Core’s PSBT implementation to close this gap. PSBTs function as an interoperability standard that allows multiple parties or devices to collaborate on constructing and signing a transaction before it is ever broadcast to the network. A flaw in how SIGHASH_SINGLE requests are processed within this standard can therefore affect any workflow that depends on Bitcoin Core’s reference code for parsing, signing, or finalizing collaborative transactions. When outputs are left unbound, the trust assumptions that underpin multi-step signing workflows erode, because a participant cannot be certain that the funds will reach the destination originally encoded in the transaction template.

As of the time of the report, the repair has been merged into the codebase but has no confirmed fixed-release destination. Users running Bitcoin Core nodes or services that rely on its PSBT functionality will need to await an official versioned release to receive the mitigation through standard binary distributions. Until then, the absence of a tagged release means that downstream wallets, custody platforms, and developer tools must independently assess whether their own validation layers prevent missing-output SIGHASH_SINGLE requests from advancing through the signing pipeline. Monitoring upcoming release notes will be necessary to determine exactly when the repair is included in a published version.

The incident highlights how subtle implementation details in long-standing transaction standards can resurface under specific input conditions. Even signature hash mechanisms that have been part of the protocol for years can reveal unexpected edge cases when combined with modern transaction-building standards. As the Bitcoin Core project prepares to package this repair into a future release, the broader focus remains on preserving the tight coupling between signatures and outputs regardless of how transactions are initially constructed.