
AI-generated summary
Partially signed Bitcoin transactions (PSBTs) allow multiple parties to contribute to a transaction without sharing private keys. SIGHASH_SINGLE is a signing mode intended to bind an input to its corresponding output, but fails when that output is missing, creating a potential authorization gap.
Bitcoin Core has added a safeguard against signing transactions that may not bind funds to the payment destination a user approved.
The change, merged into Bitcoin Core’s master development branch on Sept. 25, targets a narrow flaw in partially signed Bitcoin transactions, or PSBTs, that could produce a valid signature without protecting the intended output.
Bitcoin Optech highlighted the update on Oct. 2. The issue does not expose a user’s private key, but creates a different risk: a signature can remain valid even when the transaction’s recipient is changed under specific conditions.
The weakness involves SIGHASH_SINGLEwhich is a signing mode designed to commit an input to the output in the corresponding position. If the transaction contains no output at that position, the protection breaks down differently depending on the type of Bitcoin being spent.
For legacy inputs, the missing-output case can produce a signature over a fixed hash value. Bitcoin Core developers said that signature may then be reusable against other unspent outputs controlled by the same key when the same structural conditions are present.
SegWit v0 transactions retain stronger protections because the signature still commits to the specific coin being spent and its amount. The destination output, however, can remain unbound.
That creates an authorization problem for wallets and signing devices: software could present one payment to the user while producing a signature that does not cryptographically guarantee that the approved recipient remains unchanged.
Bitcoin Core blocks the risky signing request
Bitcoin Core already rejected the edge case through its raw-transaction signing interface. Its PSBT path, including walletprocesspsbtcould still sign it.
The new code moves the check into Bitcoin Core’s shared signature-creation logic, preventing affected legacy and SegWit v0 inputs from being signed while allowing other valid inputs in the same PSBT to proceed.
PSBTs are commonly used to coordinate transactions between software wallets, hardware devices and offline signers. They allow transaction builders to pass information to a separate signer without giving that system control of the private keys.
The fix therefore reinforces a boundary that wallet developers must enforce independently of key security: a valid cryptographic signature must commit to the transaction details the user actually authorized.
Bitcoin Improvement Proposal 174, which defines PSBTs, already tells signers to reject unacceptable signing modes and recommends SIGHASH_ALL when no alternative is specified. The Bitcoin Core change explicitly prevents this missing-output configuration from reaching the signing stage.
Users do not yet have a confirmed production release containing the safeguard. The Sept. 25 change was merged into Bitcoin Core’s development branch, while the project’s published release listings had not identified a fixed version or confirmed backport as of Oct. 4.
AI outlook — possibilities, not facts
Bitcoin Core will include this safeguard in an upcoming stable release
Likely · Within weeks

Coin Metrics has recomputed Ethereum's historical Standard Flow Metrics from genesis using updated address data, creating a distinction between retrospective reconstructions and point-in-time data availability that affects the validity of exchange outflows as trading signals, requiring analysts to track data vintage and publication timing to avoid look-ahead bias in backtests.

President Trump announced a new 'Super Intelligence Force' task force to coordinate federal AI efforts, led by former SEC Chair Jay Clayton, who previously spearheaded the agency's crypto crackdown. The force includes officials from FTC, Defense, and OPM, and will report directly to Trump and White House Chief of Staff Susie Wiles.

Near Intents has recovered $3.8 million in stolen funds after a cross-chain exploit. The service's general manager, Alex Shevchenko, successfully pressured the attacker into returning the assets by claiming they had been identified.

Chainalysis attributed the September 24 Bitget exchange hack, which stole $387 million in cryptocurrency, to North Korea-linked actors, stating the breach pushed total crypto theft by Pyongyang's hackers in 2026 past $1 billion. The firm traced the funds across multiple blockchains using in-house AI to accelerate analysis, noting the attackers moved funds through Ethereum, XRP, Zcash, and Tron before laundering via cross-chain protocols and swap services.

Pope Leo XIV stated that AI-generated art lacks the 'ontological' essence of human creation, as it relies on statistical patterns rather than lived experience. The Pope has previously issued formal teachings and established a Vatican commission to address AI ethics.

Arbitrum's Security Council temporarily blocked new Stylus contract activations on Arbitrum One and Nova following AI-assisted attack concerns, while introducing a safeguard for BoLD's one-step proofs.