The Bitcoin Core development team reported a bug in software version 31.0 affecting the -privatebroadcast feature. Under certain network conditions, this vulnerability could cause the IP address of the node initiating a transaction to become known to the receiving peer. The issue manifests only when a node runs version 31.0 with the -privatebroadcast flag enabled and transaction broadcasting is performed via the sendrawtransaction RPC command.

A fix is being prepared and will be released in update version 31.1. Until the patch is available, users utilizing the private broadcast function are advised to apply one of the suggested workarounds to eliminate the risk of data leakage. Developers emphasize that the threat is relevant exclusively to configurations meeting all the listed conditions of simultaneous use of the specific version and sending methods.

This message constitutes an official warning from the protocol creators based on an internal code audit. Currently, the information is confirmed only by the primary source; independent technical reports or data regarding actual cases of exploitation by malicious actors are absent from the provided materials.