AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Bitcoin

sign_psbt: review BIP-322 message signing requests as messages

Public commit record

What the developer wrote

Authored by Ruben Waterman

78/100 · Adequate
sign_psbt: review BIP-322 message signing requests as messages

A PSBT carrying the PSBT_GLOBAL_GENERIC_SIGNED_MESSAGE global field
(0x09, BIP-322 v1.0.0+) is now recognized as a request to sign the
BIP-322 to_sign virtual transaction, and reviewed on-screen as a
message signature instead of the normal transaction signing UX.

The security checks per BIP-322 ensure that the signatures are bound
to the intended message and can be utilized in the indended ways per
BIP-322, but result in a non-spendable transaction, since all
signatures are with SIGHASH_ALL/DEFAULT, and the first input spends
a non-existing UTXO.

A structurally invalid PSBT carrying the field is rejected; however
it is acceptable for the app to produce invalid signatures that
would not pass full BIP-322 validation, as some of the checks
require a full node anyway.

Timelocked BIP-322 signatures are not supported: the locktime and the
sequence of the first input (the "age" of the signature) must be 0.
The sequence of a proof-of-funds input has no meaning in BIP-322, so
it may be 0 or any value with the BIP-68 disable flag set, including
the final sequence implied by an omitted PSBT_IN_SEQUENCE. Any other
value would be a relative timelock with version 2, and is rejected.

Warnings for missing non-witness utxos are still shown when they
apply, in the case of proofs of funds. The first input spending the
to_spend transaction is exempt, as it is validated per BIP-322.

The 'processing' screen is adapted to show "Loading message" and
"Signing message" during signatures for BIP-322 PSBTs.

Not allowed during swap.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Salvatore Ingala <6681844+bigspider@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit adds support for signing Bitcoin messages using the BIP-322 standard inside Ledger's Bitcoin app. Instead of reviewing these as regular money transfers, the device now shows them as message signatures. The change includes safety checks to make sure the signed data is a valid BIP-322 request, cannot be spent as a real transaction, and is tied to the exact message shown to the user. It also blocks this feature when the app is being used in a cryptocurrency swap.

Recommended action

Review the BIP-322 validation logic for completeness, especially edge cases around sequence handling for version 0 vs version 2 transactions, proof-of-funds input validation, and the message streaming/display path. Consider fuzzing or formal review of validate_bip322_request() and load_bip322_message().

Security signals we found

01

New validation logic for BIP-322 message signing PSBTs

02

On-device recomputation of to_spend txid to bind signature to message

03

Rejection of non-SIGHASH_ALL/DEFAULT sighash types for BIP-322

04

Rejection of timelocked BIP-322 variants (locktime and first input sequence must be 0)

05

Proof-of-funds inputs restricted to wallet policy inputs only

06

BIP-322 signing disabled during swap/exchange flows

07

Message display uses authenticated streaming from committed PSBT global map

08

Non-witness UTXO warning exemption only for the virtual to_spend input

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 4/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.