セキュリティポータルに戻る
Solana token-transfer recipient spoofing via Address Lookup Table reference
報告日:June 1, 2026
Token transfers whose destination was referenced through a Solana lookup table displayed the lookup table's address as the recipient instead of showing that the recipient was undeterminable on the device. These transfers now use the detailed confirmation screen.
報告者 Matteo Panzeri
修正済みの脆弱性
コミュニティからの報告により、調査を行い、問題を解決しました。あなたのセキュリティは常に最優先です。
- THP pairing could be completed without the pairing code2026年6月22日
- Desktop update could install before signature verification completed2026年6月16日
- Solana account-creation confirmation completeness2026年6月14日
- Solana signing display improvement2026年6月12日
- Coordination fee cap shown on CoinJoin authorization2026年6月3日
- Open Redirect on trezor.io via /admin Cloudflare Rewrite2026年5月29日