Bitcoin Core added a safeguard in its development branch against a narrow flaw in partially signed Bitcoin transactions (PSBTs) that could allow a valid signature to survive recipient changes without exposing the private key. The issue involves the SIGHASH_SINGLE signing mode that fails to properly protect the corresponding output when it is missing. The fix, merged on September 25, blocks risky signing requests but is not yet available in production. Wallet providers must now review their own signing logic without relying on a Bitcoin Core update to enforce the same protection downstream.
Source: Read the original article

