Skip to blog content

    Quality Crypto Reporting · Primary Sources Researched

    CryptoWorkPro

    Market context

    Powered by CoinStats APIUpdated 3:15 AM

    BTC-0.83%
    $84,532
    ETH-1.49%
    $2,677
    XRP-1.10%
    $1.49
    SOL-0.96%
    $118.84
    BNB-0.79%
    $768.17
    HBAR-2.76%
    $0.1012
    QNT+1.55%
    $255.88
    TRX-0.17%
    $0.3336
    LINK-3.64%
    $13.9
    XLM-2.26%
    $0.2155
    Back to Blog
    Wallets & Security

    Bitcoin Core 31.0 PrivateBroadcast IP Leak: Privacy Fix in 31.1 Explained

    Published September 5, 2026

    Bitcoin Core 31.0 PrivateBroadcast IP Leak: Privacy Fix in 31.1 Explained Significance Bitcoin Core 31.0 introduced a privacy bug in its -privatebroadcast fe...

    Bitcoin Core 31.0 PrivateBroadcast IP Leak: Privacy Fix in 31.1 Explained

    Significance

    Bitcoin Core 31.0 introduced a privacy bug in its -privatebroadcast feature. This Bitcoin Core privatebroadcast IP leak risked exposing the IP address of transaction originators to peers. The issue affected Bitcoin wallet privacy for specific node setups. Bitcoin Core 31.1 resolves it fully.

    Node operators and wallet developers should update to Bitcoin Core 31.1. This prevents unintended IP exposure during private transaction broadcasts.

    Who, What, When, Where

    Bitcoin Core developers disclosed the bug on June 6, 2026. It impacts nodes running version 31.0 with -privatebroadcast=1. Transactions sent via the sendrawtransaction RPC triggered the risk.

    The flaw occurs on Bitcoin networks where Tor outbound connections are possible alongside direct IPv4 or IPv6. Credit goes to Eugene Siegel for discovery.

    Confirmed Evidence

    All conditions must hold for exposure:

    • Node runs Bitcoin Core 31.0 with -privatebroadcast enabled.
    • Transaction broadcast uses sendrawtransaction RPC.
    • Tor reachable for outbound connections.
    • Direct IPv4/IPv6 outbound possible, without -onlynet exclusions or -proxy routing them.
    • BIP324 v2 transport not disabled via -v2transport=0.

    Mechanism: Private broadcast selects a v2-capable IPv4/IPv6 peer. Initial Tor connection attempts v2 handshake. Failure triggers direct v1 retry, leaking IP. Onion and I2P peers remain safe. Wallet RPCs like sendtoaddress bypass private broadcast entirely.

    Context and Timeline

    June 6, 2026 advisory detailed the Bitcoin Core privatebroadcast IP leak and workarounds: disable with -privatebroadcast=0, set -v2transport=0, or proxy IPv4/IPv6 through Tor.

    July 8, 2026: Bitcoin Core 31.1 released. Notes confirm: "This release fixes an IP address leak when using the -privatebroadcast feature. Under certain circumstances connections were being made over clearnet rather than the enabled privacy network."

    Unknowns

    Number of nodes using -privatebroadcast remains unclear. No evidence shows specific peers exploiting v2 handshake failures.

    What to Watch

    Monitor future Bitcoin Core security notices for related updates.

    Editorial Risk Note

    This covers a privacy issue in an optional feature, not general wallet compromise. Verify your Bitcoin Core version directly from official sources, not this article. Featured image is a conceptual editorial illustration.

    Sources and Disclosure

    This is not security or investment advice.