Bitcoin Proposal Merged to Detect Wallet Key Leaks
The BIP461 proposal aims to secure ECDSA signatures against malicious firmware by enforcing deterministic generation.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust the current security upgrades to keep digital wallets safe from hidden key leaks?
Liam Gilligan merged Bitcoin Improvement Proposal BIP461 into the BIPs repository on September 16, 2026. The draft proposal introduces a deterministic signature procedure to prevent firmware from hiding seed material in transaction signatures.
Why it matters
Malicious hardware can currently exploit non-deterministic Elliptic Curve Digital Signature Algorithm (ECDSA) nonce choices to exfiltrate private keys within valid-looking signatures. By mandating a fixed signing process, this proposal secures wallets without requiring changes to Bitcoin consensus rules.
BIP461 limits signature size to 70 bytes in standard DER encoding to ensure consistency. It requires an independent signer to compare outputs against an expected benchmark, confirming that identical inputs produce the same deterministic signature.
The players
Liam Gilligan
A developer and contributor to the Bitcoin improvement process who managed the repository merger.
BIPs Repository
The central open-source documentation hub for Bitcoin Improvement Proposals, which track proposed protocol changes and technical standards.
The details
The proposal addresses security risks in the ECDSA (Elliptic Curve Digital Signature Algorithm — a common cryptographic method for signing digital messages) process. By mandating that firmware use a deterministic algorithm to generate signatures, the proposal prevents malicious actors from embedding secret key data within the signature's nonce (a 'number used once' in cryptography) while still passing standard verification checks.
Timeline
September 16, 2026: BIP461 was merged into the official BIPs repository.
The Tech Race
This proposal follows the established workflow of the Bitcoin Improvement Proposal standards process for documenting and reviewing protocol changes. The merger marks the initiation of the standard drafting phase within the broader ecosystem.
This proposal currently exists in a research-stage Draft status and does not affect existing wallet performance or user workflows. It provides a future pathway for developers to harden hardware wallets against malicious firmware-based key leaks.
The takeaway
The implementation of deterministic signing is a significant step toward neutralizing firmware-based key theft. Watch for the future publication of test vectors and a reference implementation, which are required for BIP461 to move from Draft to Complete status.
Further reading
For more on the evolution of protocol standards, see the latest updates in Cybersecurity.
Source note: This article includes information reported by CryptoSlate.
Live Poll
Do you trust the current security upgrades to keep digital wallets safe from hidden key leaks?







