Back to security portal
Solana token-transfer recipient spoofing via Address Lookup Table reference
Reported on June 1, 2026
Token transfers whose destination was referenced through a Solana lookup table displayed the lookup table's address as the recipient instead of showing that the recipient was undeterminable on the device. These transfers now use the detailed confirmation screen.
Reported by Matteo Panzeri
Resolved vulnerabilities
Reported by community. Investigated. Resolved. Because your security is never optional.
- THP pairing could be completed without the pairing codeJune 22, 2026
- Desktop update could install before signature verification completedJune 16, 2026
- Solana account-creation confirmation completenessJune 14, 2026
- Solana signing display improvementJune 12, 2026
- Coordination fee cap shown on CoinJoin authorizationJune 3, 2026
- Open Redirect on trezor.io via /admin Cloudflare RewriteMay 29, 2026