
Security portal
Because your security is never optional.
Join the Trezor bugbounty program
Help us secure the future of self-custody. Report vulnerabilities. Earn rewards. Follow these rules:
Act in good faith to protect user and company data.
Give us time to fix the issue before disclosing it publicly.
Avoid any fraud or harm during your research.
Report vulnerability
We reserve the right to determine the severity and eligibility of reports.
Resolved vulnerabilities
Reported by community. Investigated. Resolved. Because your security is never optional.
- Unauthenticated Remote DoS via xpub Change-Index AmplificationMay 19, 2026
- Unauthenticated Remote Memory Exhaustion via Unbounded Timestamp ArrayMay 19, 2026
- Cross-Origin Popup Takeover in Trezor Connect popupMay 3, 2026
- Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injectionMarch 25, 2026
- EIP-712 Domain Spoofing via Double-FetchMarch 21, 2026
- Open redirect on affiliate pageMarch 20, 2026