Back to security portal
Open redirect on affiliate page
Reported on March 20, 2026
An affiliate marketing tool used on our page enabled redirect to any website. An attacker could exploit this in a phishing campaign, redirecting from a legitimately looking URL to a malicious website.
Reported by Toshit Bharti
Trezor.io
Resolved vulnerabilities
Reported by community. Investigated. Resolved. Because your security is never optional.
- Unauthenticated Remote DoS via xpub Change-Index AmplificationMay 19, 2026
- Unauthenticated Remote Memory Exhaustion via Unbounded Timestamp ArrayMay 19, 2026
- Cross-Origin Popup Takeover in Trezor Connect popupMay 3, 2026
- Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injectionMarch 25, 2026
- EIP-712 Domain Spoofing via Double-FetchMarch 21, 2026
- Biometric Verification bypassed in Trezor Suite with external monitorMarch 9, 2026