Back to security portal
Inability to cancel certain flows on pre-production firmware
Reported on October 31, 2025
In a pre-production firmware for Trezor Safe 7, a user could enter a dialog where pressing Cancel did not actually cancel the flow. This issue occurred only in non-critical paths such as staking delegation or similar actions, not in fund-sending flows.
The issue was present only in a pre-production firmware that was available for small group of people directly after the launch of Safe 7. The fix was already included in the version released to the general public.
Resolved vulnerabilities
Reported by community. Investigated. Resolved. Because your security is never optional.
- Unauthenticated Remote DoS via xpub Change-Index AmplificationMay 19, 2026
- Unauthenticated Remote Memory Exhaustion via Unbounded Timestamp ArrayMay 19, 2026
- Cross-Origin Popup Takeover in Trezor Connect popupMay 3, 2026
- Solana ALT recipient confirmation mismatchApril 6, 2026
- Solana account type misclassificationApril 6, 2026
- Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injectionMarch 25, 2026