---
title: "Bitcoin Improvement Proposal BIP461 Aims to Detect Wallet Secret Leaks"
description: "BIP461, a new draft proposal for Bitcoin, introduces a deterministic ECDSA signing procedure to help identify potential wallet secret leaks by standardizing signature outputs."
author: "CryptoResearch AI"
published: "2026-10-01T02:03:05.381Z"
updated: "2026-10-01T02:03:05.382Z"
category: "bitcoin"
reading_time_minutes: 2
content_type: "editorial"
canonical: "https://cryptoresearch.news/news/bitcoin-improvement-proposal-bip461-aims-to-detect-wallet-secret-leaks"
tags: ["Bitcoin", "BIP461", "Security", "ECDSA", "Wallets"]
---

# Bitcoin Improvement Proposal BIP461 Aims to Detect Wallet Secret Leaks

> Editorial content, written by CryptoResearch.

BIP461, a new draft proposal for Bitcoin, introduces a deterministic ECDSA signing procedure to help identify potential wallet secret leaks by standardizing signature outputs.

Bitcoin improvement proposal BIP461 was merged into the BIPs repository on Sept. 16 and is currently marked as a draft. Authored by Liam Gilligan, the proposal outlines a common signing procedure for ECDSA, an existing Bitcoin signature scheme, to help detect when a wallet might be leaking secret information.

The proposal functions under existing Bitcoin consensus rules, meaning no changes to the network are required for implementation. By defining a deterministic procedure for ECDSA signatures, BIP461 creates a benchmark for how a compliant signer should behave. If independent signers produce different signatures for the same secret key and message hash, it indicates that at least one of them is not following the standard.

ECDSA allows signers flexibility when creating signatures, such as choosing a nonce. Malicious firmware can exploit this to hide key material within signatures that still pass verification. BIP461 aims to fix these choices, making it easier to spot deviations. However, the proposal notes that a mismatch does not automatically prove malice, as an honest implementation using a different valid procedure could also produce a different result.

Comparing signatures requires access to the secret key on an independent signer, which introduces a practical cost. Additionally, the proposal cannot detect conditional leaks, where a device produces compliant signatures during testing but leaks data on specific transactions. BIP461 also limits signatures to 70 bytes in standard DER encoding, excluding the one-byte sighash flag.

While the Dark Skippy disclosure previously demonstrated how corrupted firmware could embed seed material in transaction signatures, that demonstration utilized Schnorr signing. Because Taproot uses the separate BIP340 Schnorr scheme, BIP461 does not directly address that specific demonstration.

Following the September merge, a reviewer noted that the proposal requires test vectors and a reference implementation to advance to the Complete stage. For users, the potential benefit of BIP461 lies in providing a shared benchmark to make signature deviations more visible.

## Sources

- [Crypto slate](https://cryptoslate.com/new-bitcoin-upgrade-catches-hidden-key-leaks-hiding-the-exact-fix/)

---

Published by CryptoResearch. Canonical version: https://cryptoresearch.news/news/bitcoin-improvement-proposal-bip461-aims-to-detect-wallet-secret-leaks
