
Security portal
Because your security is never optional.
Join the Trezor bugbounty program
Help us secure the future of self-custody. Report vulnerabilities. Earn rewards. Follow these rules:
Act in good faith to protect user and company data.
Give us time to fix the issue before you disclose it publicly.
Avoid any fraud or harm during your research.
Report vulnerability
We reserve the right to assess the severity and eligibility of reports.
Resolved vulnerabilities
Reported by the community. Investigated. Resolved. Because your security is never optional.
- Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injectionMarch 25, 2026
- Open redirect on affiliate pageMarch 20, 2026
- Biometric Verification bypassed in Trezor Suite with external monitorMarch 9, 2026
- Insufficient entropy on Trezor Model One with 12/18 wordsFebruary 6, 2026
- Bug in multisig verificationJanuary 10, 2026
- Inability to cancel certain flows on pre-production firmwareOctober 31, 2025