Trezor / 2026-08-16 (reported)
Authenticity proofs not bound to individual chips
One valid proof could satisfy checks intended for different chips.
Read disclosure ↗Legacy One and Model T findings do not automatically apply to the Safe family. Chip-level research and full-wallet compromise are identified separately.
One valid proof could satisfy checks intended for different chips.
Read disclosure ↗Pairing could complete without knowing the displayed code.
Read disclosure ↗Chip firmware verification could be bypassed.
Read disclosure ↗Some anti-tampering countermeasures could be bypassed.
Read disclosure ↗Kraken reported extraction of PIN-encrypted seed material through a microcontroller fault on Trezor One and Model T. Physical access is a prerequisite.
Read disclosure ↗Faults in USB handling could expose device memory.
Read disclosure ↗This is a selected public research archive, not a complete inventory or a rating of current product security.