This commit simply updates a timestamp and a matching numeric version marker used for Ethereum token/network definition files. There is no code logic change, no security fix, and no vulnerability introduced.
This commit is a documentation-only changelog update for the Trezor firmware release 2.12.2 and prodtest 0.3.8. It does not change any code, but it lists several security fixes that are part of this release. The most important ones affect …
Bitcoin external input misidentification in signingBitcoin RBF replacement transaction allows new external outputsSolana hidden instruction parameters not confirmed by user
This commit simply adds firmware version 2.12.2 to a list of released versions in a JSON file. It does not change any code, fix any bug, or alter security behavior. There is nothing here that could directly affect user security.
This commit replaces a binary file called secmon.bin for the T3W1 hardware model with a different signed version. The change is described as a routine chore to upload a properly signed secure monitor binary. No source code was modified, an…
This commit simply adds a new approved digital signature for translation data files used by Trezor hardware wallets. It is a routine metadata update with no visible security bug or code change.
This commit only updates documentation: it moves a bug-fix note from a draft changelog file into the published changelogs for firmware version 2.12.3. No program code is changed, so this commit by itself cannot introduce or fix a security …
This commit simply adds a new firmware version number (2.12.3) and lists which Trezor hardware models it supports in a release metadata file. There is no code change, no bug fix, and no security-related content in the diff.
This commit simply adds a new digital signature entry to a JSON file that records approved translation bundles for the Trezor hardware wallet firmware. There is no code change, no bug fix, and no indication of a security issue. It appears …
This commit only updates the expected test result hashes in a single file used for automated UI testing. It does not change any firmware, application, or cryptographic code. There is no direct security relevance visible in the commit itsel…
This commit fixes a bug in LDK's Lightning channel reconnection logic after a splice (a way to resize a channel's on-chain funds). If one peer had already received the splice signatures but the other had not, and then they disconnected and…
Protocol-state inconsistency on reconnection after splice signature exchangePotential channel stall/force-close due to quiescence not being exited before commitment updateFuzzer-discovered edge case in Lightning splicing retransmission
This commit fixes how Trezor firmware parses certain Ethereum transaction data types—specifically arrays of byte blobs (bytes[]) and arrays of strings (string[])—when showing clear signing details on the device screen. Before the fix, the …
Incorrect offset handling in transaction data decoderPotential display of misleading clear-signing informationDouble pointer dereference in dynamic array parsing
This commit removes unused code and unreachable safety checks from the Ethereum clear-signing module. The removed function (parse_uint256_array) was never actually used, and the type-check guards it supported could never be triggered. Ther…
A quiet fix may be responsible caution—or it may leave users unaware that their assets were ever at risk. CommitWatch preserves the evidence, adds context, and tracks whether vendors disclose, acknowledge, and learn.