Bitcoin Core developers have merged a fix for a narrow flaw in signature handling that could let the recipient of a payment change without invalidating the transaction's signature, according to reporting from CryptoSlate published on October 4, 2026. The issue sits in how the software processes a specific signing request, not in private-key security, so it is a design gap rather than a stolen-key event.
The patch lands at a quiet moment for the market. Bitcoin traded at $85,415 as of October 4, 2026, up 0.7% on the day, with the broader Fear and Greed index reading 68 ("Greed"). The fix drew little price reaction because it touches wallet-construction plumbing rather than the economics of the asset.
The gap sits in SIGHASH_SINGLE
Every Bitcoin transaction carries a signature hash type that tells the network which parts of the transaction the signature actually commits to. SIGHASH_SINGLE is one of those types. It signs a single output that corresponds to the input being signed, which is useful when different parties assemble a transaction in pieces.
The problem, per CryptoSlate's account, is a missing-output case. When a SIGHASH_SINGLE request points at an output that is not present, the recipient can be left unbound. A signature that does not firmly commit to where the money goes leaves room for the destination to be altered after signing while the signature still checks out as valid. The practical risk is funds arriving somewhere the signer did not intend.
This is a policy and construction issue. The cryptography itself is not broken, and nobody needs your keys to exploit a signing request that was built without the right output committed to it.
The repair is in PSBT handling
The merged fix targets Partially Signed Bitcoin Transactions, the standard format wallets and signing devices use to pass an in-progress transaction between parties before it is finalized. PSBT is the connective tissue for multisig setups, hardware wallets, and collaborative transactions, which is exactly where a signer and a transaction builder are different steps in the same flow.
By repairing how the missing-output SIGHASH_SINGLE case is handled at the PSBT layer, Core closes the gap at the point where transactions are assembled rather than relying on every downstream wallet to catch it independently. As analysis, the fix being upstream in Core matters because wallets and signing tools inherit Core's behavior; the correction propagates as software updates roll out rather than requiring every integrator to rediscover the same edge case.
A narrow bug, not a chain-wide emergency
Worth keeping in proportion: this is a narrow signing flaw, not a consensus failure or a break in Bitcoin's core security model. There is no indication in the reporting that keys are at risk or that the supply is affected. The exposure is concentrated in workflows that lean on SIGHASH_SINGLE and multi-step signing, which is a minority of everyday transactions.
Still, the category of bug is instructive. A valid signature on the wrong transaction is a harder failure to spot than a theft, because every automated check passes. For anyone running custom signing infrastructure, exchange withdrawal systems, or self-custody tooling that constructs PSBTs, the takeaway is to track Core releases and update signing software rather than assuming a valid signature guarantees a correct destination.
The episode also lands in a busy stretch for Bitcoin infrastructure security. Developers recently flagged active attacks on unpatched Lightning nodes, another case where keeping node and wallet software current was the whole defense.
Overview
Bitcoin Core merged a fix for a SIGHASH_SINGLE flaw that could leave a payment's recipient unbound when a signing request referenced a missing output, allowing the destination to change while the signature stayed valid. The repair sits in PSBT handling, so it addresses the problem where transactions are assembled. It is a signing-policy bug, not a key compromise or a consensus break, and it affects a minority of flows that rely on SIGHASH_SINGLE and multi-step signing. The clearest action for anyone running signing infrastructure is to update to patched Core-derived software and treat a valid signature as insufficient proof that funds are headed where intended.



