AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 78 Bitcoin

Merge pull request #1044 from kdmukai/psbt_multisig_output_claims

Public commit record

What the developer wrote

Authored by Nick Klockenga

78/100 · Adequate
Merge pull request #1044 from kdmukai/psbt_multisig_output_claims

[security] Store multiple verified derivation path entries per input/output; reject all decoy keys
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This update fixes a security gap in how SeedSigner checks who owns each part of a Bitcoin transaction. A malicious transaction file (PSBT) could previously include an extra, real-but-irrelevant key belonging to your seed as a 'decoy' in a multisig change output. The old code only kept the first matching key it found, so it might miss the decoy and wrongly approve the output as your change, potentially letting funds slip to an attacker. The new code records every matching key claim, verifies each one against the actual output script, and rejects the transaction if any claim doesn't line up or if there are too many claims.

Recommended action

Review and merge promptly; this is a security-hardening fix for a real PSBT parsing weakness in multisig change detection. After merge, ensure the new tests pass and consider a release note or advisory about improved multisig PSBT verification.

Security signals we found

01

Fixes multisig PSBT decoy-key ownership-verification bypass

02

Rejects surplus derivation path entries that do not map to the output script

03

Adds explicit handling for multiple verified derivation paths per scope

04

Includes new and updated unit tests for decoy placement variants

05

Commit message explicitly tags [security]

Risk score

Why this scored 78/100

Our methodology →
Potential impact 24/30
Exploitability 18/25
Stealth signal 12/15
Affected reach 10/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.