Voltar para o portal de segurança
Solana token-transfer recipient spoofing via Address Lookup Table reference
Reportado em June 1, 2026
Token transfers whose destination was referenced through a Solana lookup table displayed the lookup table's address as the recipient instead of showing that the recipient was undeterminable on the device. These transfers now use the detailed confirmation screen.
Reportado por Matteo Panzeri
Vulnerabilidades resolvidas
Reportado pela comunidade. Investigado. Resolvido. Porque sua segurança nunca é opcional.
- THP pairing could be completed without the pairing code22 de junho de 2026
- Desktop update could install before signature verification completed16 de junho de 2026
- Solana account-creation confirmation completeness14 de junho de 2026
- Solana signing display improvement12 de junho de 2026
- Coordination fee cap shown on CoinJoin authorization3 de junho de 2026
- Open Redirect on trezor.io via /admin Cloudflare Rewrite29 de maio de 2026