October 2, 2026
Share

New Bitcoin upgrade catches hidden key leaks hiding the exact fix

A new Bitcoin improvement proposal, BIP461, aims to detect hidden wallet secret key leaks by standardizing ECDSA signatures without requiring network consensus changes.

New Bitcoin upgrade catches hidden key leaks hiding the exact fix

A fresh Bitcoin improvement proposal, designated BIP461, aims to simplify the detection of covert pathways that leak wallet secrets. The draft proposal outlines a standardized signing methodology for ECDSA, which is a pre-existing signature framework on the Bitcoin network.

Independent, compliant signing devices are expected to generate matching signatures for any identical secret key and message hash. This establishes a reliable baseline to spot anomalies that might otherwise conceal secret key exfiltration.

Put together by Liam Gilligan, the proposal was integrated into the BIPs repository on Sept. 16, though it currently retains a Draft status. Because its signatures function seamlessly within current Bitcoin consensus rules, adopting this signing approach demands no modifications to network consensus.

Comparing signatures for deviations

The ECDSA protocol grants a signer several options when generating a valid signature, such as selecting the nonce—a temporary random value utilized during the signing process. Compromised or malicious firmware can abuse this flexibility to smuggle key data inside signatures that continue to pass standard validation checks. BIP461 addresses this vulnerability by fixing these variables through a defined, deterministic process.

The fact that Bitcoin accepts a signature offers no guarantee that the key remained secure during its generation. Utilizing a shared specification provides a predictable expected output against which a signer’s performance can be evaluated.

Performing this check necessitates identical inputs and the exact same standard, which includes exposing the secret key to a separate, independent signer. This additional exposure represents a practical drawback of replicating the signature. Discrepancies between outputs for the same key and message hash indicate that at least one of the signers is failing to adhere to BIP461.

It is worth noting that an honest implementation relying on a different valid ECDSA procedure might also yield conflicting results. While any mismatch triggers the need to audit compliance, the root cause remains ambiguous. The comparison by itself cannot pinpoint a compromised device or prove that theft occurred.

Related Reading

No dice? Your Bitcoin hardware wallet is probably not as secure as you thought it was

Furthermore, the mandated algorithm limits signatures to a maximum of 70 bytes using standard DER encoding, which does not count Bitcoin’s single-byte sighash flag.

The Dark Skippy vulnerability previously highlighted how compromised firmware can smuggle seed data directly into transaction signatures. When first publishing their findings, the researchers noted they had not observed the exploit being actively used in the wild.

Although the original Dark Skippy demonstration relied on Schnorr signatures, BIP461 focuses exclusively on ECDSA. Because Taproot utilizes the distinct BIP340 Schnorr scheme, this draft does not directly offer a standard fix for that specific proof-of-concept.

In their discussions on mitigations, the researchers cautioned that a malicious signer might choose to leak data selectively on a targeted transaction. Consequently, a rogue device could easily generate fully compliant signatures during routine testing while leaking secrets on a completely separate transaction.

When the proposal was merged in September, a reviewer pointed out that moving BIP461 forward to a Complete status requires both test vectors and a reference implementation.

For everyday wallet users, the core benefit lies in establishing a communal benchmark that surfaces hidden irregularities. Realizing that potential, however, still hinges on proper implementations and cross-checks that carefully weigh detection boundaries alongside the inherent dangers of handling sensitive secrets.

Frequently Asked Questions

01What is BIP461?

BIP461 is a draft Bitcoin improvement proposal authored by Liam Gilligan that defines a standard, deterministic signing procedure for ECDSA to help detect hidden key leaks.

02Does BIP461 require a Bitcoin consensus change?

No. The signatures produced under BIP461 operate entirely under existing Bitcoin consensus rules, meaning no consensus upgrade is required for implementation.

03Can BIP461 definitively prove that a wallet has been compromised?

No. While mismatched signatures indicate that a signer is not following BIP461 or is using a different valid procedure, the comparison alone cannot conclusively identify a malicious device or prove that a theft occurred.

Share

Leave a Reply

Your email address will not be published. Required fields are marked *