Bitcoin Core lists BIP-461 deterministic ECDSA as implemented since v0.17
Bitcoin Core merged pull request #36377 on 30 September, adding BIP-461 to its list of BIPs the software implements. The change is documentation only: the pull request notes that the BIP's mailing-list discussion names Core's own pull request #13666, released in v0.17.0, as an existing implementation.
BIP-461, "Deterministic ECDSA Signatures", is a draft by Liam Gilligan, assigned its number on 12 August 2026. It specifies an ECDSA signing algorithm whose output is fully determined by the secret key and the message. The nonce is derived with the RFC 6979 construction; the signer then regenerates the signature with a new nonce until r is "low" (below 2^255) and normalizes s to its low form. The result is at most 70 bytes when DER-encoded, rather than 72 for an arbitrary valid signature.
The motivation is not size but trust. Under current consensus rules a signer has freedom in choosing the nonce, and two possible values of s follow from each r. The BIP notes that a malicious signer can exploit that freedom to produce signatures that leak key material. A standardized deterministic algorithm removes the freedom: a key holder can load the same key into two independent signers, sign the same message on both and compare the results, and any difference shows that at least one of them is not following the specification. As the BIP puts it, standardization is what enables that check, because a nonstandard algorithm has nothing to be cross-checked against.

Why it matters
Hardware wallets and signing services are exactly where a leaking nonce would be hardest to spot. By writing down the grinding-and-normalization procedure Core has used since 2018, BIP-461 turns an implementation detail into a test any user with two devices can run.