AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 68 Bitcoin

Merge pull request #1046 from kdmukai/2026_09_psbt_nested_singlesig_change

Public commit record

What the developer wrote

Authored by Nick Klockenga

88/100 · Strong
Merge pull request #1046 from kdmukai/2026_09_psbt_nested_singlesig_change

[security] Verify nested single sig change that omits its redeem script
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit fixes a security bug in how SeedSigner recognizes 'change' outputs on bitcoin transactions when using older nested SegWit single-signature wallets. A change output is change that comes back to your own wallet; the device must identify it correctly so it does not look like money being sent to a stranger. Because of an optional field in the PSBT data format, a valid change output could be mistaken for a plain pay-to-script-hash output and treated as an external spend. The fix lets the parser consider these outputs as change candidates and then verifies ownership by rebuilding the expected script from the seed's own key, rather than trusting the PSBT's missing or misleading redeem script. The commit also adds tests showing that malicious PSBTs that claim ownership but pay someone else are rejected.

Recommended action

Review the ownership rebuild path in _parse_outputs to confirm it is invoked for all outputs passing _is_change_candidate, and ensure that no other policy-shape comparison bypasses the carve-out. Consider adding tests for partially signed or multi-input PSBTs where only some inputs are p2sh-p2wpkh. Users should upgrade to a release containing this commit before signing nested SegWit single-sig PSBTs produced by wallets that omit the redeem script.

Security signals we found

01

Change-output misclassification could cause users to believe change is being sent to an external address

02

PSBT field omission (redeem_script) used to bypass change verification

03

Fix shifts from trust in PSBT metadata to cryptographic rebuild from seed-derived key

04

Tests include adversarial PSBTs that claim ownership but pay foreign keys

05

Commit title and message explicitly tag [security]

Risk score

Why this scored 68/100

Our methodology →
Potential impact 22/30
Exploitability 14/25
Stealth signal 11/15
Affected reach 9/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.