All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog.
- Reduce the choices to select wordcount when unlocking repeated backup to 20 or 33. #4099
- Changed prefix of public key returned by
get_ecdh_session_key
for curve25519. #4093 - Renamed MATIC to POL, following a network upgrade. #4151
- Removed
display_random
feature. #4119
- Fix persistent word when going to previous word during recovery process. #3859
- Fix display orientation south. #3990
- Fixed SLIP-10 fingerprints for ed25519 and curve25519. #4093
- Improve precision of PIN timeout countdown. #4000
- Solana: added support for deprecated AToken Create
rent_sysvar
argument. #3976
- Expose value of the Optiga SEC counter in
Features
message.
- Reworked PIN processing.
- CoSi functionality. #3442
- Increase Optiga read timeout to avoid spurious RSODs.
- Added basic support for STM32U5. #3370
- Cardano: Added support for tagged sets in CBOR (tag 258). #3496
- Cardano: Added support for Conway certificates. #3496
- Added ability to request Shamir backups with any number of groups/shares. #3636
- Added support for repeated backups. #3640
- Support extendable backup flag in SLIP-39.
- Cardano: Increased max URL length to 128 bytes. #3496
- Translate also texts for PIN progress loaders. #3520
- Add translations capability. #3206
- Stellar: add support for
StellarClaimClaimableBalanceOp
. #3434 - Add loader to homescreen when locking the device. #3440
- Allow for going back to previous word in recovery process. #3458
- Clear sign ETH staking transactions on Everstake pool. #3517
- Send BIP-380 descriptor in GetPublicKey response. #3539
- Display descriptors for BTC Taproot public keys. #3475
- Improved UI of multiple Solana instructions. #3445
- Solana multisig instruction warning will be displayed before instruction details are displayed. #3445
- Fixed Solana Memo instruction being unknown - it will now be recognized and displayed properly. #3445
- Add missing semicolon character to the passphrase entry. #3477
- Added Solana support. #3359
- Always display Ethereum fees in Gwei. #3246
- Fix invalid encoding of signatures from Optiga. #3411
- Re-added missing address confirmation screens. #3424
- Support interaction-less upgrade. #2919
- Allowed non-zero address index in Cardano staking paths. #3242
- Turn the screen off when device is locked, to prolong OLED life. #3377
- Integrate Optiga into PIN verification. #3296
- Implement UI. #2610
- QR code display when exporting XPUBs. #3047
- Added hw model field to all vendor headers. #3048
- Added firmware update without interaction. #3205
- Split builds of different parts to use simple util.s assembler, while FW+bootloader use interconnected ones. #3205
- Add support for address chunkification in Receive and Sign flow. #3237
- Implement device authentication. #3255
- Use Optiga as a source of randomness in seed generation. #3256
- Update to MicroPython 1.19.1. #2341
- Introduce multisig warning to BTC receive flow. #2937
- Introduce multiple account warning to BTC send flow. #2937
- MUE coin support. #3216
- Signed Ethereum network and token definitions from host. #15
- CoSi collective signatures on Model T. #450
- Support Ledger Live legacy derivation path
m/44'/coin_type'/0'/account
. #1749 - Updated bootloader to 2.1.0. #1901
- Show source account path in BTC signing. #2151
- Show path for internal outputs in BTC signing. #2152
- Add model info to image and check when installing bootloader, prevent bootloader downgrade. #2623
- Allow proposed Casa m/45' multisig paths for Bitcoin and Ethereum. #2682
- Support for external reward addresses in Cardano CIP-36 registrations. #2692
- Add address confirmation screen to EIP712 signing flow. #2818
- Add the possibility of rebooting the device into bootloader mode. #2841
- Switched to redesigned, Rust-based user interface. #1922
- Ignore channel ID in U2F. #2205
- Micropython code optimizations to make the code take less flash space. #2525
- CPU Frequency increased to 180 MHz. #2587
- Fixed display blinking by increasing backlight PWM frequency. #2595
- Updated FAT FS library to R0.15. #2611
- Auto-lock timer is no longer restarted by USB messages, only touch screen activity. #2651
- Updated UI and terminology in Cardano CIP-36 registrations. #2692
- Ethereum's EIP-712 signing no longer restricts the maximum field size to 1024 bytes. #2746
- Force basic attestation in FIDO2 for google.com. #2834
- Enable Trezor to work as a FIDO2 authenticator for Apple. #2784
- Fix RNG for bootloader and make insecure PRNG opt-in, not opt-out. #2899
- Match and validate script type of change-outputs in Bitcoin signing.
- Optimize touch controller communication. #262
- Add SLIP-0025 CoinJoin accounts. #2289
- Show red error header when USB data pins are not connected. #2366
- Add support for Zcash unified addresses. #2398
- Using hardware acceleration (dma2d) for rendering. #2414
- Add stack overflow detection. #2427
- Show fee rate when replacing transaction. #2442
- Support SetBusy message. #2445
- Add serialize option to SignTx. #2507
- Support for Cardano CIP-36 governance registration format. #2561
- Implement CoinJoin requests. #2577
- Extend decimals of fee rate to 2 digits. #2486
- Display only sat instead of sat BTC. #2487
- Remove old BulletProof code from Monero. #2570
- Add model R emulator #2230
- Add support for Monero HF15 features. #2232
- Add basic Trezor Model R hardware support #2243
- Show the fee rate on the signing confirmation screen. #2249
- Jump and stay in bootloader from firmware through SVC call reverse trampoline. #2284
- Expose raw pixel access to Rust #2297
- Add RGB LED for Model R #2300
- Boardloader capabilities structure #2324
- Support for Cardano Babbage era transaction items #2354
- Add "Show All"/"Show Simple" choice to Cardano transaction signing #2355
- Documentation for embedded C+Rust debugging #2380
- Show thousands separator when displaying large amounts. #2394
- Refactor and cleanup of Monero code. #642
- Remove power-down power-up cycle from touch controller initialization in firmware #2130
- Updated secp256k1-zkp. #2261
- Cardano internal refactors #2313
- Allow Cardano's
required_signers
in ordinary and multisig transactions Allow Cardano'sdatum_hash
in non-script outputs #2354
- Removed support for obsolete Monero hardfork 12 and below #642
- Remove firmware dumping capability. #2433
- (Emulator) Emulator window will always react to shutdown events, even while waiting for USB packets. #973
- Ensure correct order when verifying external inputs in Bitcoin signing. #2415
- Fix Decred transaction weight calculation. #2422
- Support Bitcoin payment requests. #1430
- Show "signature is valid" dialog when VerifyMessage succeeds. #1880
- Support ownership proofs for Taproot addresses. #1944
- Add extra check for Taproot scripts validity. #2077
- Support Electrum signatures in VerifyMessage. #2100
- Support Cardano Alonzo-era transactions (Plutus). #2114
- Support unverified external inputs. #2144
- Support Zcash version 5 transaction format #2166
- Add firmware hashing functionality. #2239
- Ensure input's script type and path match the scriptPubKey. #1018
- Automatically choose best size and encoding for QR codes. #1751
- Bitcoin bech32 addresses are encoded in lower-case for QR codes. #1751
- Full type-checking for Python code (except Monero app). #1939
- [debuglink] Do not wait for screen refresh when disabling layout watching. #2135
- GAME, NIX and POLIS support. #2181
- EIP-1559 transaction correctly show final Hold to Confirm screen. #2020
- Fix sighash computation in proofs of ownership. #2034
- Fix domain-only EIP-712 hashes (i.e. when
primaryType
=EIP712Domain
). #2036 - Support EIP-712 messages where a struct type is only used as an array element. #2167
- Fix a coin loss vulnerability related to replacement transactions with multisig inputs and unverified external inputs.
- Trezor will refuse to sign UTXOs that do not match the provided derivation path (e.g., transactions belonging to a different wallet, or synthetic transaction inputs). #1018
- Convert timestamps to human-readable dates and times. #741
- Support no_script_type option in SignMessage. #1586
- Show address confirmation in SignMessage. #1586
- Support pre-signed external Taproot inputs in Bitcoin. #1656
- Show warning dialog in SignMessage if a non-standard path is used. #1656
- Support spending from Taproot UTXOs. #1656
- Support GetAddress for Taproot addresses. #1656
- Support sending to Taproot addresses. #1656
- Support replacement transactions with Taproot inputs in Bitcoin. #1656
- Support of BIP-340 Schnorr signatures (using secp256k1-zkp). #1678
- Support for Taproot descriptors. #1710
- Ethereum: support 64-bit chain IDs. #1771
- Support for Cardano multi-sig transactions, token minting, script addresses, multi-sig keys, minting keys and native script verification. #1772
- For compatibility with other Cardano implementations, it is now possible to specify which Cardano derivation type is used. #1783
- Full type-checking for Ethereum app. #1794
- Ethereum - support for EIP712 - signing typed data. #1835
- Stellar: add support for StellarManageBuyOfferOp and StellarPathPaymentStrictSendOp. #1838
- Add script_pubkey field to TxInput message. #1857
- Cardano root is derived together with the normal master secret. #1231
- Update QR-code-generator library version. #1639
- Faster ECDSA signing and verification (using secp256k1-zkp). #1678
- Most Stellar fields are now required on protobuf level. #1755
- Type-checking enabled for apps.stellar. #1755
- Updated micropython to version 1.17. #1789
- Errors from protobuf decoding are now more expressive. #1811
- Disable previous transaction streaming in Bitcoin if all internal inputs are Taproot. #1656
- Remove BELL, ZNY support. #1872
- Remove altcoin message definitions from bitcoin-only build. #1633
- Ethereum: make it optional to view the entire data field when signing transaction. #1819
- Ensure that the user is always warned about non-standard paths.
- Avoid accidental build with broken stack protector. #1642
- Session must be configured with Initialize(derive_cardano=True), otherwise Cardano functions will fail. #1231
- Timebounds must be set for a Stellar transaction. #1755
- Cardano derivation type must be specified for all Cardano functions. #1783
- Ethereum non-EIP-155 cross-chain signing is no longer supported. #1794
- Stellar: rename StellarManageOfferOp to StellarManageSellOfferOp, StellarPathPaymentOp to StellarPathPaymentStrictReceiveOp and StellarCreatePassiveOfferOp to StellarCreatePassiveSellOfferOp. #1838
- [emulator] Added option to dump detailed Micropython memory layout #1557
- Support for Ethereum EIP1559 transactions #1604
- Re-enabled Firo support #1767
- Converted all remaining code to common layouts. #1545
- Memory optimization of BTC signing and CBOR decoding. #1581
- Cardano transaction parameters are now streamed into the device one by one instead of being sent as one large object #1683
- Thanks to transaction streaming, Cardano now supports larger transactions (tested with 62kB transactions, but supposedly even larger transactions are supported) #1683
- Refactor RLP codec for better clarity and some small memory savings. #1704
- Refer to
m/48'/...
multisig derivation paths as BIP-48 instead of Purpose48. #1744
- Removed support for Lisk #1765
- Disable TT features (SD card, SBU, FAT) for T1 build. #1163
- It is no longer possible to sign Cardano transactions containing paths belonging to multiple accounts (except for Byron to Shelley migration) #1683
- Add new rpId to Binance's FIDO definition. #1705
- Don't use format strings in keyctl-proxy #1707
- Properly respond to USB events while on a paginated screen. #1708
- Due to transaction streaming in Cardano, it isn't possible to return the whole serialized transaction anymore. Instead the transaction hash, transaction witnesses and auxiliary data supplement are returned and the serialized transaction needs to be assembled by the client. #1683
- ButtonRequest for multi-page views contains number of pages. #1671
- Converted altcoin apps to common layout code. #1538
- Reimplement protobuf codec and library in Rust #1541
- Cardano: Reintroduce maximum transaction output size limitation #1606
- Cardano: Improve address validation and decouple it from address derivation #1606
- Cardano: Remove sorting of policies, assets and withdrawals. Rather add them to the transaction in the order they arrived in. #1672
- Cardano: Forbid withdrawals with the same path in a single transaction #1672
- Unify Features.revision reporting with legacy #1620
- Fix red screen on shutdown. #1658
- Empty passphrase is properly cached in Cardano functions #1659
- Ensure that all testnet coins use SLIP-44 coin type 1.
- Disable all testnet coins from accessing Bitcoin paths.
- Restrict BIP-45 paths to Bitcoin and coins with strong replay protection.
- Fix operation source account encoding in Stellar.
- Decred staking. #1249
- Locking the device by holding finger on the homescreen for 2.5 seconds. #1404
- Public key to ECDHSessionKey. #1518
- Rust FFI for MicroPython. #1540
- Support PIN of unlimited length. #1167
- Allow decreasing the output value in RBF transactions. #1491
- Cardano: Allow stake pool registrations with zero margin. #1502
- Cardano: Assets are now shown as CIP-0014. #1510
- Random delays use ChaCha-based DRBG instead of HMAC-DRBG. #1554
- Reduce memory fragmentation by clearing memory after every workflow. #1565
- Update some FIDO icons. #1456
- Compatibility paths for Unchained Capital. #1467
- CoinJoin preauthorization and signing flow. #1053
- Value of the
safety-checks
setting to theFeatures
message. #1193 - ERC20 tokens show contract address for confirmation. Unknown ERC20 tokens show wei amount. #800
- Replacement transaction signing for replace-by-fee and PayJoin. #1292
- Support for Output Descriptors export. #1363
- Paginated display for signing/verifying long messages. #1271
- Show Ypub/Zpub correctly for multisig GetAddress. #1415
- Show amounts in mBTC, uBTC and sat denominations. #1369
- The
safety-checks
setting gained new possible valuePromptTemporarily
which overrides safety checks until device reboot. #1133 - Protobuf codec now enforces
required
fields and pre-fills default values. #379 TxAck
messages are now decoded into "polymorphic" subtypes instead of the commonTxAck
type.- Bump nanopb dependency to 0.4.3. #1105
- BIP-32 paths must now match a pre-defined path schema to be considered valid. #1184
- Minimum auto-lock delay to 1 minute. The former value of 10 seconds still applies for debug builds. #1351
- It is again possible to sign for Ethereum clones that are not officially supported. #1335
- Bump nanopb dependency to 0.4.4. #1402
- Automatic breaking text on whitespace. #1384
- Introduced limit of 32 characters for device label. #1399
- PIVX support
- dropped debug-only
DebugLinkShowText
functionality
- Path warning is not shown on
GetAddress(show_display=False)
call. #1206 - Settings are also erased from RAM when device is wiped. #1322
- Support for the upcoming Monero hard fork. #1246
- Running the frozen version of the emulator doesn't need arguments. #1115
- XVG support. #1165
- Hard limit on transaction fees. Can be disabled using
safety-checks
. #1087
- Print inverted question mark for non-printable characters.
- Remove pre-fill bar from text rendering functions. #1173
- Display coin name when signing or verifying messages. #1159
- Allow spending coins from Bitcoin paths if the coin has implemented strong replay protection via
SIGHASH_FORKID
. #1188
- Remove ETP, GIN, PTC, ZEL support.
- Drop support for signing Zcash v3 transactions. #982
- CRW addresses are properly generated. #1139
- Fix boot loop after uploading invalid homescreen. #1118
- Allow 49/x not 49/x' for Casa. #1190
- Make sure Homescreen is properly initialized. #1095
- Show non-empty passphrase on device when it was entered on host.
- Show warning if nLockTime is set but ineffective due to all nSequence values being 0xffffffff.
- Soft lock. #958
- Auto lock. #1027
- Dedicated
initialized
field in storage. - Support EXTERNAL transaction inputs with a SLIP-0019 proof of ownership. #1052
- Support pre-signed EXTERNAL transaction inputs.
- Support multiple change-outputs. #1098
- New option
safety-checks
allows overriding "forbidden key path" errors. #1126 - Support for Cardano Shelley. #948
Features.pin_cached
renamed tounlocked
.- Forbid all settings if the device is not yet initialized. #1056
- Rewrite USB codec and Protobuf decoder to be more memory-efficient. #1089
- Allow compatibility namespaces for Casa and Green Address.
- Deprecate
overwintered
field inSignTx
andTxAck
.
- Generated protobuf classes now do not contain deprecated fields.
- Fix cancel icon in PIN dialog. #1042
- Fix repaint bug in QR code rendering. #1067
- Fix QR code overlapping in Monero address. monero-gui#2960, #1074
- Re-introduce ability to spend pre-Overwinter UTXO on Zcash-like coins. #1030
- Refactor Bitcoin signing
- Refactor Keychain into a decorator
- Stream previous tx also for Segwit inputs
- Cache up to 10 sessions (passphrases)
- SD card protection
- Show xpubs with multisig get_address
- Introduce FatFS (version 0.14)
- Support Ed25519 in FIDO2
- Passphrase redesign
- Upgrade MicroPython to 1.12
- Properly limit passphrase to 50 bytes and not 50 characters
- Monero: add confirmation dialog for unlock_time
- Add feature to retrieve the next U2F counter.
- Wipe code.
- Add screen for time bounds in Stellar.
- Fix continuous display blinking with Android in U2F.
- U2F UX improvements.
- Rework Recovery persistence internally.
- Remove unused ButtonRequest.data field.
- Disallow changing of settings via dry-run recovery.
- Support Tezos 005-BABYLON hardfork.
- Show XPUBs in GetAddress for multisig.
- Security improvements.
- Fix low memory issue.
- Super Shamir.
- FIDO2.
- FIDO2 credential management via trezorctl.
- BackupType in Features.
- Refactor Shamir related codebase.
- Fix storage keys module visibility bug (6ad329) introduced in 2.1.3 (46e4c0) which was breaking upgrades.
- Binance Coin support.
- Introduce Features.Capabilities.
- Fix for sluggish U2F authentication when using Shamir.
- Fix UI for Shamir with 33 words.
- Fix Wanchain signing.
- Shamir Backup reset device hotfix.
- Shamir Backup with Recovery persistence.
- Touchscreen freeze fix.
- Fix display of non-divisible OMNI amounts.
- Shamir Backup feature preview.
- EOS support.
- Set screen rotation via user setting.
- Display non-zero locktime values.
- Don't rotate the screen via swipe gesture.
- More strict path validations.
- Hotfix for touchscreen freeze.
- Monero UI fixes.
- Speed and memory optimizations.
- New coins: ATS, AXE, FLO, GIN, KMD, NIX, PIVX, REOSC, XPM, XSN, ZCL.
- New ETH tokens.
- Ripple, Stellar, Cardano and NEM fixes.
- Included bootloader 2.0.3.
- Security improvements.
- Upgraded to new storage format.
- Add support for OMNI layer: OMNI/MAID/USDT.
- Add support for new coins: BTX, CPC, GAME, RVN.
- Add support for new Ethereum tokens.
- Included bootloader 2.0.2.
- Fix Monero payment ID computation.
- Fix issue with touch screen and flickering.
- Small Monero and Segwit bugfixes.
- Monero support.
- Cardano support.
- Stellar support.
- Ripple support.
- Tezos support.
- Decred support.
- Groestlcoin support.
- Zencash support.
- Zcash sapling hardfork support.
- Implemented seedless setup.
- Bitcoin Cash cashaddr support.
- Zcash Overwinter hardfork support.
- NEM support.
- Lisk support.
- Show warning on home screen if PIN is not set.
- Support for new coins (BTCP, FUJI, VTC, VIA, XZC).
- Support for new Ethereum networks (EOSC, ETHS, ELLA, CTL, EGEM, WAN).
- Support for 500+ new Ethereum tokens.
- Add special characters to passphrase keyboard.
- Fix layout for Ethereum transactions.
- Fix public key generation for SSH and GPG.
- First public release.