Confirmation-Binding Flaw in Trezor Safe Products by SatoshiLabs
CVE-2026-65058
5.9MEDIUM
What is CVE-2026-65058?
The Trezor Safe firmware for models 3, 5, and 7 exhibits a confirmation-binding flaw during Ethereum transaction signing. In the 'sign_tx' and 'sign_tx_eip1559' flows, the device only validates the initial portion of the calldata, while the full signed transaction incorporates additional streamed calldata. This discrepancy allows an attacker to present a victim with altered calldata and potentially modify the signed transaction without the victim's awareness. The issue has been addressed and resolved in a recent firmware update.
Affected Version(s)
Safe 3 0 < 70c9b0c
Safe 5 0 < 70c9b0c
Safe 7 0 < 70c9b0c
