AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 68 Bitcoin

Admit bare p2sh outputs as nested single sig change

Public commit record

What the developer wrote

Authored by kdmukai

85/100 · Strong
Admit bare p2sh outputs as nested single sig change

A p2sh-p2wpkh output's scriptPubKey is a bare p2sh hash. BIP-174 leaves the
redeem script optional on an output, and without it _get_policy types the output
as plain p2sh, which does not match a p2sh-p2wpkh wallet policy. The output then
never reaches the ownership check at all. Two things follow. The user's own
change is displayed as a payment out to a stranger. And an output that keeps a
genuine claim on this seed while repointing its scriptPubKey escapes the
ownership-contradiction refusal by dropping one optional field.

Nested single sig is the only script type whose identity depends on an optional
field its proof does not read: the rebuild is p2sh(p2wpkh(K)) from our own seed
at the claimed path and the inputs' policy, so the missing field is a
discriminator rather than evidence. For p2sh-p2wsh the discriminator and the
proof material are the same field, so its absence is genuine silence and
correctly out of reach.

_policy_shape_matches becomes _is_change_candidate, an instance method, since it
now reads the inputs' policy and the output's verified derivation paths. Beside
the unchanged shape comparison it admits a bare p2sh output under a p2sh-p2wpkh
wallet that carries no m-of-n, supplies exactly one derivation path entry, and
holds one verified claim on this seed. Everything below is unchanged: the
rebuild decides, honest change is counted as change, and a repointed output
raises PSBTOutputOwnershipContradictionError.

The single-entry conditions are what keep that refusal safe. A genuine multisig
output carries one derivation path entry per cosigner, so it never reaches the
contradiction check by this route. The shape that would is a bare p2sh output
withholding both scripts while annotating a single key of a multisig, and no
surveyed coordinator emits one. Every coordinator but Bitcoin Core annotates
only its own change output. Core annotates an output because a descriptor solved
its script, so it holds all n key origins and writes them.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
The short version

What changed, and why it matters

This commit fixes a bug in SeedSigner's PSBT transaction parser. When a user spent from a 'nested single-signature SegWit' wallet (p2sh-p2wpkh), a change output could omit an optional redeem script. The parser then misread the output as a plain, unrelated p2sh payment, so it showed the user's own change as money going to a stranger. Worse, an attacker could craft a PSBT that still claimed the change belonged to the user's seed while actually paying a different address, and the old code would not detect the contradiction. The patch lets these bare p2sh outputs through to the full ownership check, which rebuilds the expected address from the seed and catches any mismatch.

Recommended action

Treat this commit as a security fix and include it in the next release. Users should upgrade before signing p2sh-p2wpkh PSBTs, especially those produced by coordinators that omit the output redeem script. Review any past signed transactions from nested SegWit wallets where change was shown as an external spend.

Security signals we found

01

UI misrepresentation: user's own change displayed as external payment

02

Missing ownership-contradiction check on crafted PSBT output

03

Optional BIP-174 field used as policy discriminator, causing type mismatch

04

Patch adds explicit guard conditions (single derivation, verified, no multisig m field) before bypassing shape check

05

Tests cover both the benign and malicious cases

Risk score

Why this scored 68/100

Our methodology →
Potential impact 22/30
Exploitability 14/25
Stealth signal 11/15
Affected reach 9/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.