Back to security portal
Solana signing display improvement
Reported on June 12, 2026
Certain Solana account-creation instructions did not surface all signed fields on the device's confirmation screen, weakening the What-You-See-Is-What-You-Sign guarantee for those flows. The affected screens now display the complete set of relevant fields prior to confirmation.
Resolved vulnerabilities
Reported by community. Investigated. Resolved. Because your security is never optional.
- Unauthenticated Remote DoS via xpub Change-Index AmplificationMay 19, 2026
- Unauthenticated Remote Memory Exhaustion via Unbounded Timestamp ArrayMay 19, 2026
- Ethereum's SLIP-24 payment-request branch in production firmware signs attacker calldata under cover of verified-swap UIMay 16, 2026
- Cross-Origin Popup Takeover in Trezor Connect popupMay 3, 2026
- Lock bypass in SD-protect-only configuration allows signing after LockDevice/autolockApril 14, 2026
- Solana ALT recipient confirmation mismatchApril 6, 2026