Regresar al centro de seguridad

EIP-712 Domain Spoofing via Double-Fetch

Reportada en March 21, 2026

A flaw in EIP-712 typed-data signing allowed domain spoofing on device confirmation. A compromised host could show a trusted domain name/version on the Trezor screen while making the device sign data for a different, attacker-controlled domain. This mismatch could mislead users into approving signatures they did not intend, potentially enabling unauthorized actions such as malicious permit approvals and fund theft.

Reportada por Florian Pradines