Bitcoin Just Patched a Flaw That Could Drain Your Wallet Without Ever Touching Your Keys

Bitcoin Core developers quietly merged a fix for a vulnerability that allowed funds to be silently redirected to a different destination, no private key theft required.

The bug lives inside PSBT, the Partially Signed Bitcoin Transaction format that wallets, hardware signers, and multi-sig setups rely on every single day. A missing-output edge case in SIGHASH_SINGLE, a specific signature hashing mode, left recipients effectively "unbound" from a transaction. In plain English: a malicious actor could manipulate where your Bitcoin lands without ever compromising your keys. You sign. They redirect.

That is not a theoretical attack vector. That is a practical threat to every user relying on PSBT-based workflows, including the majority of hardware wallet users and anyone in a multi-signature arrangement.

Why This Matters More Than Most "Bug Fix" Headlines

Most security patches close holes that require sophisticated access. This one is different. The SIGHASH_SINGLE missing-output quirk is a known cryptographic edge case, meaning someone who understood the spec could weaponize it without exotic tools. The attack does not scream. There are no stolen keys to detect, no obvious red flag in your wallet interface. Funds simply end up somewhere else.

The fix has been merged into Bitcoin Core's codebase, which is the good news. The less comfortable news: there is no confirmed release version attached to this patch yet. That means the repair exists in code but has not shipped to end users through an official update cycle. Wallets and services that bundle Bitcoin Core will need to pull the fix, test it, and push it downstream before everyday users are protected.

The Part Nobody Is Saying Out Loud

Multi-sig setups and hardware wallet integrations are everywhere right now. Institutional custody solutions, treasury management tools, and self-custody power users all lean on PSBT. The timing of this disclosure matters because adoption of these tools has never been higher. The attack surface just got a patch, but the window between "merged" and "deployed" is exactly where risk lives.

What You Should Do Right Now

Watch for Bitcoin Core's next release announcement. If you run a node or any software that bundles Core, update the moment a tagged release ships. If you are using a hardware wallet with PSBT support, check your vendor's security advisory page this week. Ledger, Trezor, and Coldcard all operate in this stack.

Do not panic. Do stay alert. A fix that exists in a repository but not in your wallet is not a fix yet.

This is the kind of patch that gets buried under price action. Do not let it.