Understand custody · Collaborative signing

When the Order of Two PSBTs Decided Whether a Signature Worked

PSBT allows several programs or devices to prepare one transaction without sharing private keys. In one edge case, Bitcoin Core combined those records differently depending on which file came first.

EDITORIAL OVERVIEW · Prepared by the project editors from the sources listed below.

A transaction assembled in parts

One program can create a PSBT, a hardware wallet can sign it, and another computer can merge the records and finalize the payment. The format is especially important for multisignature custody, shared control, and isolated signing devices.

Bitcoin Core uses combinepsbt to merge several versions of a PSBT. In August 2026, a developer found an edge case where the result depended on the order of the supplied files.

The field that was not copied

A PSBT can specify a sighash type, describing which parts of a transaction a signature commits to. The ordinary form usually covers all inputs and outputs, but other types exist, including ALL|ANYONECANPAY.

When merging, Bitcoin Core copied almost every missing optional field from one record to the other. PSBT_IN_SIGHASH_TYPE was the exception. If the first file lacked the field while the second contained a signature using a non-default sighash, the signature could be copied without its type.

Finalization then applied the default and rejected the otherwise valid signature as incompatible. Reversing the same two files could allow the operation to succeed.

Why funds did not disappear

The bug did not expose private keys, alter confirmed transactions, or let an outsider take bitcoin. It affected transaction preparation: a valid signature could be rejected and the PSBT left incomplete.

In complex custody arrangements, every participant may perform the correct action while the loss of one metadata field still prevents final assembly.

Making order irrelevant

The fix copies the sighash type from the second PSBT when it is absent from the first. Tests now cover both merge orders.

Reviewers accepted the change into Bitcoin Core's main branch on September 9, 2026. That confirms the development code was repaired; it does not mean every already-installed binary release contains the change.

The small patch restores an important property of PSBT: combining compatible information should not produce a different result merely because the user listed one file before another.

Collaborative signing must preserve not only the signature, but also the exact description of what it commits to.

Sources and verification

  1. Bitcoin Core PR #36076: preserve sighash type when merging inputs ↗
  2. Bitcoin Optech Newsletter #423 ↗

This article describes a repaired PSBT preparation bug, not a theft of funds or a compromise of private keys.

Unless stated otherwise, the text, conclusions, structure and editorial arrangement were created by the project editors. Facts, quotations and source materials remain attributable to their authors and rights holders.

← Back to the rubric