BIP461 aims to expose covert key leaks by standardizing Bitcoin ECDSA signing

technology⚖️ Neutral

⏱ 2 min read

$BTC
▲ 0.07%
$83,506

The draft would make independent signers produce identical ECDSA signatures for the same input—creating a compliance check that can flag hidden key exfiltration without a consensus change.


A new Bitcoin improvement proposal, BIP461, seeks to make covert key exfiltration easier to spot by standardizing how wallets create ECDSA signatures. Authored by Liam Gilligan, the proposal was merged into the Bitcoin BIPs repository on Sept. 16 and remains marked Draft.

The draft defines a deterministic signing procedure so two independent, compliant signers produce identical signatures for the same secret key and message hash. That creates an expected output against which a device’s behavior can be checked. Different results for the same inputs indicate that at least one signer is not following BIP461.

The need for a common procedure arises from ECDSA’s degrees of freedom. Signers choose a temporary nonce during signing, and compromised firmware can hide key material in that choice while still producing signatures that verify. BIP461 fixes those choices through a specified deterministic algorithm. Because it stays within Bitcoin’s existing verification rules, it requires no consensus change to adopt.

The test introduces trade‑offs. Reproducing a signature requires access to the same secret key on another independent signer, an additional exposure that implementers must manage. And a mismatch alone does not prove a device is malicious or that theft occurred; an honest implementation using another valid ECDSA method can also disagree. A divergence is a signal for investigation, not a verdict.

Scope matters. The proposal addresses ECDSA signatures, while Taproot uses the separate BIP340 Schnorr scheme. The Dark Skippy disclosure demonstrated how corrupted firmware could embed seed material in transaction signatures using Schnorr, and the researchers said they had not seen the technique in the wild. BIP461 does not directly standardize a remedy for Schnorr signatures.

The draft also constrains signature size, prescribing outputs that fit within 70 bytes in standard DER encoding, excluding Bitcoin’s one‑byte sighash flag.

What to watch next

The practical impact depends on uptake. Signals include wallet‑vendor adoption of BIP461, auditor requirements that incorporate deterministic ECDSA checks, and any companion proposal that extends the approach to Schnorr/Taproot so both major signing paths are covered.


This content is for informational purposes only and does not constitute financial advice.

🧠 HafidWatch Take

BIP461 offers a meaningful step toward detecting covert key leaks in ECDSA signatures, but its impact is inherently limited without addressing Schnorr-based signatures used in Taproot. Even when implemented, a signature mismatch doesn’t automatically signal foul play; it could reflect benign differences in valid signing methods. Consequently, adopting BIP461 improves the chances of spotting compromised ECDSA signers but cannot alone eliminate risk across Bitcoin’s entire signing ecosystem, leaving a significant blind spot until a comparable standard covers Schnorr signatures.

Daily crypto intelligence. Before the market opens.

Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.

✓ Free forever  ·  ✓ No spam  ·  ✓ 50+ sources monitored

Want it faster? Join the community:

Type above and press Enter to search. Press Esc to cancel.