Bitcoin proposal BIP461 defines a deterministic procedure for producing ECDSA signatures, giving independent compliant signers an expected output for the same secret key and message hash. That comparison could expose departures from the procedure that conceal key leakage in otherwise valid signatures. Authored by Liam Gilligan and merged into the BIPs repository on Sept. 16, the proposal remains a Draft. Its signatures comply with existing Bitcoin consensus rules, so the procedure would require no consensus change.
Why it matters
ECDSA lets a signer make choices, including the nonce used during signing, while still producing a signature Bitcoin accepts. Malicious firmware could use that flexibility to hide key material in a transaction signature. BIP461 fixes those choices through a common procedure, making deviations easier to spot.
The check has limits. Reproducing a signature requires the same inputs and an independent signer with access to the secret key, creating another point of exposure. A mismatch shows that at least one signer did not follow BIP461, but an honest signer using a different valid ECDSA procedure could also disagree. A match confirms only the signature tested, not the device's behavior on future transactions.
Market impact
BIP461 offers wallet developers and users a potential security benchmark, not proof that a wallet is free of malicious firmware. The Dark Skippy disclosure showed how corrupted firmware could embed seed material in signatures, though researchers said they had not seen the technique in the wild. Their original demonstration used Schnorr signatures; BIP461 covers ECDSA and does not directly address Bitcoin's Taproot Schnorr scheme.
A reviewer said test vectors and a reference implementation were needed for the draft to advance to Complete. Its practical value depends on compliant implementations and careful comparisons that account for both the limits of detection and the risks of handling secret keys.
Frequently asked questions
-
How would BIP461 help detect a hidden wallet key leak?
It specifies how compliant ECDSA signers should produce a signature for the same secret key and message hash. A different output flags a departure from that procedure for investigation.
-
Would implementing BIP461 require a Bitcoin consensus change?
No. Signatures produced under the draft work within existing Bitcoin consensus rules.
-
Does a BIP461 signature mismatch prove a wallet is malicious?
No. A mismatch shows that at least one signer is not following BIP461, but an honest implementation using another valid ECDSA procedure could also produce a different result.
-
What is the risk in comparing signatures across devices?
Reproducing the signature requires identical inputs and an independent signer with access to the secret key. Giving another signer that access creates an additional exposure risk.
-
Does BIP461 address the Dark Skippy Schnorr demonstration?
Not directly. BIP461 specifies ECDSA signing, while the original Dark Skippy demonstration used Schnorr signatures. A matching ECDSA signature also confirms only the sample tested.
CryptoSlate