however, not all parts of a transaction are signed. modifying those parts allows one to create a valid transaction with the same bitcoin transferring effect, but with a different overall hash.
the hash of the entire transaction is used as a transaction id.
so a modified transaction would have a different id.
some bitcoin management software (a wallet) loses track of transfers, because those transfers don't occur under the transaction-id it expected.
the implication is that some bitcoin services could get confused about who they've successfully sent bitcoins to.
an attacker could socially engineer a "robbery" by transmitting a mutation of an official withdrawal transaction, then appealing to the helpdesk of that service that their withdrawal never went through. it did go through - just under a different transaction id.