Confirmation-Binding Flaw in Trezor Safe Products by SatoshiLabs
CVE-2026-65058

5.9MEDIUM

Key Information:

Vendor

Trezor

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65058?

The Trezor Safe firmware for models 3, 5, and 7 exhibits a confirmation-binding flaw during Ethereum transaction signing. In the 'sign_tx' and 'sign_tx_eip1559' flows, the device only validates the initial portion of the calldata, while the full signed transaction incorporates additional streamed calldata. This discrepancy allows an attacker to present a victim with altered calldata and potentially modify the signed transaction without the victim's awareness. The issue has been addressed and resolved in a recent firmware update.

Affected Version(s)

Safe 3 0 < 70c9b0c

Safe 5 0 < 70c9b0c

Safe 7 0 < 70c9b0c

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oleh Konko, 1seal
.