/** * elFinder translation template * use this file to create new translation * submit new translation via https://github.com/Studio-42/elFinder/issues * or make a pull request */ /** * XXXXX translation * @author Translator Name * @version 201x-xx-xx */ (function(root, factory) { if (typeof define === 'function' && define.amd) { define(['elfinder'], factory); } else if (typeof exports !== 'undefined') { module.exports = factory(require('elfinder')); } else { factory(root.elFinder); } }(this, function(elFinder) { elFinder.prototype.i18.REPLACE_WITH_xx_OR_xx_YY_LANG_CODE = { translator : 'Translator name <translator@email.tld>', language : 'Language of translation in your language', direction : 'ltr', dateFormat : 'M d, Y h:i A', // will show like: Mar 13, 2012 05:27 PM fancyDateFormat : '$1 h:i A', // will show like: Today 12:25 PM nonameDateFormat : 'ymd-His', // noname upload will show like: 120513-172700 messages : { /********************************** errors **********************************/ 'error' : 'Error', 'errUnknown' : 'Unknown error.', 'errUnknownCmd' : 'Unknown command.', 'errJqui' : 'Invalid jQuery UI configuration. Selectable, draggable and droppable components must be included.', 'errNode' : 'elFinder requires DOM Element to be created.', 'errURL' : 'Invalid elFinder configuration! URL option is not set.', 'errAccess' : 'Access denied.', 'errConnect' : 'Unable to connect to backend.', 'errAbort' : 'Connection aborted.', 'errTimeout' : 'Connection timeout.', 'errNotFound' : 'Backend not found.', 'errResponse' : 'Invalid backend response.', 'errConf' : 'Invalid backend configuration.', 'errJSON' : 'PHP JSON module not installed.', 'errNoVolumes' : 'Readable volumes not available.', 'errCmdParams' : 'Invalid parameters for command "$1".', 'errDataNotJSON' : 'Data is not JSON.', 'errDataEmpty' : 'Data is empty.', 'errCmdReq' : 'Backend request requires command name.', 'errOpen' : 'Unable to open "$1".', 'errNotFolder' : 'Object is not a folder.', 'errNotFile' : 'Object is not a file.', 'errRead' : 'Unable to read "$1".', 'errWrite' : 'Unable to write into "$1".', 'errPerm' : 'Permission denied.', 'errLocked' : '"$1" is locked and can not be renamed, moved or removed.', 'errExists' : 'Item named "$1" already exists.', 'errInvName' : 'Invalid file name.', 'errInvDirname' : 'Invalid folder name.', // from v2.1.24 added 12.4.2017 'errFolderNotFound' : 'Folder not found.', 'errFileNotFound' : 'File not found.', 'errTrgFolderNotFound' : 'Target folder "$1" not found.', 'errPopup' : 'Browser prevented opening popup window. To open file enable it in browser options.', 'errMkdir' : 'Unable to create folder "$1".', 'errMkfile' : 'Unable to create file "$1".', 'errRename' : 'Unable to rename "$1".', 'errCopyFrom' : 'Copying files from volume "$1" not allowed.', 'errCopyTo' : 'Copying files to volume "$1" not allowed.', 'errMkOutLink' : 'Unable to create a link to outside the volume root.', // from v2.1 added 03.10.2015 'errUpload' : 'Upload error.', // old name - errUploadCommon 'errUploadFile' : 'Unable to upload "$1".', // old name - errUpload 'errUploadNoFiles' : 'No files found for upload.', 'errUploadTotalSize' : 'Data exceeds the maximum allowed size.', // old name - errMaxSize 'errUploadFileSize' : 'File exceeds maximum allowed size.', // old name - errFileMaxSize 'errUploadMime' : 'File type not allowed.', 'errUploadTransfer' : '"$1" transfer error.', 'errUploadTemp' : 'Unable to make temporary file for upload.', // from v2.1 added 26.09.2015 'errNotReplace' : 'Object "$1" already exists at this location and can not be replaced by object with another type.', // new 'errReplace' : 'Unable to replace "$1".', 'errSave' : 'Unable to save "$1".', 'errCopy' : 'Unable to copy "$1".', 'errMove' : 'Unable to move "$1".', 'errCopyInItself' : 'Unable to copy "$1" into itself.', 'errRm' : 'Unable to remove "$1".', 'errTrash' : 'Unable into trash.', // from v2.1.24 added 30.4.2017 'errRmSrc' : 'Unable remove source file(s).', 'errExtract' : 'Unable to extract files from "$1".', 'errArchive' : 'Unable to create archive.', 'errArcType' : 'Unsupported archive type.', 'errNoArchive' : 'File is not archive or has unsupported archive type.', 'errCmdNoSupport' : 'Backend does not support this command.', 'errReplByChild' : 'The folder "$1" can\'t be replaced by an item it contains.', 'errArcSymlinks' : 'For security reason denied to unpack archives contains symlinks or files with not allowed names.', // edited 24.06.2012 'errArcMaxSize' : 'Archive files exceeds maximum allowed size.', 'errResize' : 'Unable to resize "$1".', 'errResizeDegree' : 'Invalid rotate degree.', // added 7.3.2013 'errResizeRotate' : 'Unable to rotate image.', // added 7.3.2013 'errResizeSize' : 'Invalid image size.', // added 7.3.2013 'errResizeNoChange' : 'Image size not changed.', // added 7.3.2013 'errUsupportType' : 'Unsupported file type.', 'errNotUTF8Content' : 'File "$1" is not in UTF-8 and cannot be edited.', // added 9.11.2011 'errNetMount' : 'Unable to mount "$1".', // added 17.04.2012 'errNetMountNoDriver' : 'Unsupported protocol.', // added 17.04.2012 'errNetMountFailed' : 'Mount failed.', // added 17.04.2012 'errNetMountHostReq' : 'Host required.', // added 18.04.2012 'errSessionExpires' : 'Your session has expired due to inactivity.', 'errCreatingTempDir' : 'Unable to create temporary directory: "$1"', 'errFtpDownloadFile' : 'Unable to download file from FTP: "$1"', 'errFtpUploadFile' : 'Unable to upload file to FTP: "$1"', 'errFtpMkdir' : 'Unable to create remote directory on FTP: "$1"', 'errArchiveExec' : 'Error while archiving files: "$1"', 'errExtractExec' : 'Error while extracting files: "$1"', 'errNetUnMount' : 'Unable to unmount.', // from v2.1 added 30.04.2012 'errConvUTF8' : 'Not convertible to UTF-8', // from v2.1 added 08.04.2014 'errFolderUpload' : 'Try the modern browser, If you\'d like to upload the folder.', // from v2.1 added 26.6.2015 'errSearchTimeout' : 'Timed out while searching "$1". Search result is partial.', // from v2.1 added 12.1.2016 'errReauthRequire' : 'Re-authorization is required.', // from v2.1.10 added 24.3.2016 'errMaxTargets' : 'Max number of selectable items is $1.', // from v2.1.17 added 17.10.2016 'errRestore' : 'Unable to restore from the trash. Can\'t identify the restore destination.', // from v2.1.24 added 3.5.2017 'errEditorNotFound' : 'Editor not found to this file type.', // from v2.1.25 added 23.5.2017 'errServerError' : 'Error occurred on the server side.', // from v2.1.25 added 16.6.2017 'errEmpty' : 'Unable to empty folder "$1".', // from v2.1.25 added 22.6.2017 'moreErrors' : 'There are $1 more errors.', // from v2.1.44 added 9.12.2018 'errMaxMkdirs' : 'You can create up to $1 folders at one time.', // from v2.1.58 added 20.6.2021 /******************************* commands names ********************************/ 'cmdarchive' : 'Create archive', 'cmdback' : 'Back', 'cmdcopy' : 'Copy', 'cmdcut' : 'Cut', 'cmddownload' : 'Download', 'cmdduplicate' : 'Duplicate', 'cmdedit' : 'Edit file', 'cmdextract' : 'Extract files from archive', 'cmdforward' : 'Forward', 'cmdgetfile' : 'Select files', 'cmdhelp' : 'About this software', 'cmdhome' : 'Root', 'cmdinfo' : 'Get info', 'cmdmkdir' : 'New folder', 'cmdmkdirin' : 'Into New Folder', // from v2.1.7 added 19.2.2016 'cmdmkfile' : 'New file', 'cmdopen' : 'Open', 'cmdpaste' : 'Paste', 'cmdquicklook' : 'Preview', 'cmdreload' : 'Reload', 'cmdrename' : 'Rename', 'cmdrm' : 'Delete', 'cmdtrash' : 'Into trash', //from v2.1.24 added 29.4.2017 'cmdrestore' : 'Restore', //from v2.1.24 added 3.5.2017 'cmdsearch' : 'Find files', 'cmdup' : 'Go to parent folder', 'cmdupload' : 'Upload files', 'cmdview' : 'View', 'cmdresize' : 'Resize & Rotate', 'cmdsort' : 'Sort', 'cmdnetmount' : 'Mount network volume', // added 18.04.2012 'cmdnetunmount': 'Unmount', // from v2.1 added 30.04.2012 'cmdplaces' : 'To Places', // added 28.12.2014 'cmdchmod' : 'Change mode', // from v2.1 added 20.6.2015 'cmdopendir' : 'Open a folder', // from v2.1 added 13.1.2016 'cmdcolwidth' : 'Reset column width', // from v2.1.13 added 12.06.2016 'cmdfullscreen': 'Full Screen', // from v2.1.15 added 03.08.2016 'cmdmove' : 'Move', // from v2.1.15 added 21.08.2016 'cmdempty' : 'Empty the folder', // from v2.1.25 added 22.06.2017 'cmdundo' : 'Undo', // from v2.1.27 added 31.07.2017 'cmdredo' : 'Redo', // from v2.1.27 added 31.07.2017 'cmdpreference': 'Preferences', // from v2.1.27 added 03.08.2017 'cmdselectall' : 'Select all', // from v2.1.28 added 15.08.2017 'cmdselectnone': 'Select none', // from v2.1.28 added 15.08.2017 'cmdselectinvert': 'Invert selection', // from v2.1.28 added 15.08.2017 'cmdopennew' : 'Open in new window', // from v2.1.38 added 3.4.2018 'cmdhide' : 'Hide (Preference)', // from v2.1.41 added 24.7.2018 /*********************************** buttons ***********************************/ 'btnClose' : 'Close', 'btnSave' : 'Save', 'btnRm' : 'Remove', 'btnApply' : 'Apply', 'btnCancel' : 'Cancel', 'btnNo' : 'No', 'btnYes' : 'Yes', 'btnDiscard': 'Discard changes', 'btnMount' : 'Mount', // added 18.04.2012 'btnApprove': 'Goto $1 & approve', // from v2.1 added 26.04.2012 'btnUnmount': 'Unmount', // from v2.1 added 30.04.2012 'btnConv' : 'Convert', // from v2.1 added 08.04.2014 'btnCwd' : 'Here', // from v2.1 added 22.5.2015 'btnVolume' : 'Volume', // from v2.1 added 22.5.2015 'btnAll' : 'All', // from v2.1 added 22.5.2015 'btnMime' : 'MIME Type', // from v2.1 added 22.5.2015 'btnFileName':'Filename', // from v2.1 added 22.5.2015 'btnSaveClose': 'Save & Close', // from v2.1 added 12.6.2015 'btnBackup' : 'Backup', // fromv2.1 added 28.11.2015 'btnRename' : 'Rename', // from v2.1.24 added 6.4.2017 'btnRenameAll' : 'Rename(All)', // from v2.1.24 added 6.4.2017 'btnPrevious' : 'Prev ($1/$2)', // from v2.1.24 added 11.5.2017 'btnNext' : 'Next ($1/$2)', // from v2.1.24 added 11.5.2017 'btnSaveAs' : 'Save As', // from v2.1.25 added 24.5.2017 /******************************** notifications ********************************/ 'ntfopen' : 'Open folder', 'ntffile' : 'Open file', 'ntfreload' : 'Reload folder content', 'ntfmkdir' : 'Creating folder', 'ntfmkfile' : 'Creating files', 'ntfrm' : 'Delete items', 'ntfcopy' : 'Copy items', 'ntfmove' : 'Move items', 'ntfprepare' : 'Checking existing items', 'ntfrename' : 'Rename files', 'ntfupload' : 'Uploading files', 'ntfdownload' : 'Downloading files', 'ntfsave' : 'Save files', 'ntfarchive' : 'Creating archive', 'ntfextract' : 'Extracting files from archive', 'ntfsearch' : 'Searching files', 'ntfresize' : 'Resizing images', 'ntfsmth' : 'Doing something', 'ntfloadimg' : 'Loading image', 'ntfnetmount' : 'Mounting network volume', // added 18.04.2012 'ntfnetunmount': 'Unmounting network volume', // from v2.1 added 30.04.2012 'ntfdim' : 'Acquiring image dimension', // added 20.05.2013 'ntfreaddir' : 'Reading folder infomation', // from v2.1 added 01.07.2013 'ntfurl' : 'Getting URL of link', // from v2.1 added 11.03.2014 'ntfchmod' : 'Changing file mode', // from v2.1 added 20.6.2015 'ntfpreupload': 'Verifying upload file name', // from v2.1 added 31.11.2015 'ntfzipdl' : 'Creating a file for download', // from v2.1.7 added 23.1.2016 'ntfparents' : 'Getting path infomation', // from v2.1.17 added 2.11.2016 'ntfchunkmerge': 'Processing the uploaded file', // from v2.1.17 added 2.11.2016 'ntftrash' : 'Doing throw in the trash', // from v2.1.24 added 2.5.2017 'ntfrestore' : 'Doing restore from the trash', // from v2.1.24 added 3.5.2017 'ntfchkdir' : 'Checking destination folder', // from v2.1.24 added 3.5.2017 'ntfundo' : 'Undoing previous operation', // from v2.1.27 added 31.07.2017 'ntfredo' : 'Redoing previous undone', // from v2.1.27 added 31.07.2017 'ntfchkcontent' : 'Checking contents', // from v2.1.41 added 3.8.2018 /*********************************** volumes *********************************/ 'volume_Trash' : 'Trash', //from v2.1.24 added 29.4.2017 /************************************ dates **********************************/ 'dateUnknown' : 'unknown', 'Today' : 'Today', 'Yesterday' : 'Yesterday', 'msJan' : 'Jan', 'msFeb' : 'Feb', 'msMar' : 'Mar', 'msApr' : 'Apr', 'msMay' : 'May', 'msJun' : 'Jun', 'msJul' : 'Jul', 'msAug' : 'Aug', 'msSep' : 'Sep', 'msOct' : 'Oct', 'msNov' : 'Nov', 'msDec' : 'Dec', 'January' : 'January', 'February' : 'February', 'March' : 'March', 'April' : 'April', 'May' : 'May', 'June' : 'June', 'July' : 'July', 'August' : 'August', 'September' : 'September', 'October' : 'October', 'November' : 'November', 'December' : 'December', 'Sunday' : 'Sunday', 'Monday' : 'Monday', 'Tuesday' : 'Tuesday', 'Wednesday' : 'Wednesday', 'Thursday' : 'Thursday', 'Friday' : 'Friday', 'Saturday' : 'Saturday', 'Sun' : 'Sun', 'Mon' : 'Mon', 'Tue' : 'Tue', 'Wed' : 'Wed', 'Thu' : 'Thu', 'Fri' : 'Fri', 'Sat' : 'Sat', /******************************** sort variants ********************************/ 'sortname' : 'by name', 'sortkind' : 'by kind', 'sortsize' : 'by size', 'sortdate' : 'by date', 'sortFoldersFirst' : 'Folders first', 'sortperm' : 'by permission', // from v2.1.13 added 13.06.2016 'sortmode' : 'by mode', // from v2.1.13 added 13.06.2016 'sortowner' : 'by owner', // from v2.1.13 added 13.06.2016 'sortgroup' : 'by group', // from v2.1.13 added 13.06.2016 'sortAlsoTreeview' : 'Also Treeview', // from v2.1.15 added 01.08.2016 /********************************** new items **********************************/ 'untitled file.txt' : 'NewFile.txt', // added 10.11.2015 'untitled folder' : 'NewFolder', // added 10.11.2015 'Archive' : 'NewArchive', // from v2.1 added 10.11.2015 'untitled file' : 'NewFile.$1', // from v2.1.41 added 6.8.2018 'extentionfile' : '$1: File', // from v2.1.41 added 6.8.2018 'extentiontype' : '$1: $2', // from v2.1.43 added 17.10.2018 /********************************** messages **********************************/ 'confirmReq' : 'Confirmation required', 'confirmRm' : 'Are you sure you want to permanently remove items?
This cannot be undone!', 'confirmRepl' : 'Replace old file with new one? (If it contains folders, it will be merged. To backup and replace, select Backup.)', 'confirmRest' : 'Replace existing item with the item in trash?', // fromv2.1.24 added 5.5.2017 'confirmConvUTF8' : 'Not in UTF-8
Convert to UTF-8?
Contents become UTF-8 by saving after conversion.', // from v2.1 added 08.04.2014 'confirmNonUTF8' : 'Character encoding of this file couldn\'t be detected. It need to temporarily convert to UTF-8 for editting.
Please select character encoding of this file.', // from v2.1.19 added 28.11.2016 'confirmNotSave' : 'It has been modified.
Losing work if you do not save changes.', // from v2.1 added 15.7.2015 'confirmTrash' : 'Are you sure you want to move items to trash bin?', //from v2.1.24 added 29.4.2017 'confirmMove' : 'Are you sure you want to move items to "$1"?', //from v2.1.50 added 27.7.2019 'apllyAll' : 'Apply to all', 'name' : 'Name', 'size' : 'Size', 'perms' : 'Permissions', 'modify' : 'Modified', 'kind' : 'Kind', 'read' : 'read', 'write' : 'write', 'noaccess' : 'no access', 'and' : 'and', 'unknown' : 'unknown', 'selectall' : 'Select all items', 'selectfiles' : 'Select item(s)', 'selectffile' : 'Select first item', 'selectlfile' : 'Select last item', 'viewlist' : 'List view', 'viewicons' : 'Icons view', 'viewSmall' : 'Small icons', // from v2.1.39 added 22.5.2018 'viewMedium' : 'Medium icons', // from v2.1.39 added 22.5.2018 'viewLarge' : 'Large icons', // from v2.1.39 added 22.5.2018 'viewExtraLarge' : 'Extra large icons', // from v2.1.39 added 22.5.2018 'places' : 'Places', 'calc' : 'Calculate', 'path' : 'Path', 'aliasfor' : 'Alias for', 'locked' : 'Locked', 'dim' : 'Dimensions', 'files' : 'Files', 'folders' : 'Folders', 'items' : 'Items', 'yes' : 'yes', 'no' : 'no', 'link' : 'Link', 'searcresult' : 'Search results', 'selected' : 'selected items', 'about' : 'About', 'shortcuts' : 'Shortcuts', 'help' : 'Help', 'webfm' : 'Web file manager', 'ver' : 'Version', 'protocolver' : 'protocol version', 'homepage' : 'Project home', 'docs' : 'Documentation', 'github' : 'Fork us on GitHub', 'twitter' : 'Follow us on Twitter', 'facebook' : 'Join us on Facebook', 'team' : 'Team', 'chiefdev' : 'chief developer', 'developer' : 'developer', 'contributor' : 'contributor', 'maintainer' : 'maintainer', 'translator' : 'translator', 'icons' : 'Icons', 'dontforget' : 'and don\'t forget to take your towel', 'shortcutsof' : 'Shortcuts disabled', 'dropFiles' : 'Drop files here', 'or' : 'or', 'selectForUpload' : 'Select files', 'moveFiles' : 'Move items', 'copyFiles' : 'Copy items', 'restoreFiles' : 'Restore items', // from v2.1.24 added 5.5.2017 'rmFromPlaces' : 'Remove from places', 'aspectRatio' : 'Aspect ratio', 'scale' : 'Scale', 'width' : 'Width', 'height' : 'Height', 'resize' : 'Resize', 'crop' : 'Crop', 'rotate' : 'Rotate', 'rotate-cw' : 'Rotate 90 degrees CW', 'rotate-ccw' : 'Rotate 90 degrees CCW', 'degree' : '°', 'netMountDialogTitle' : 'Mount network volume', // added 18.04.2012 'protocol' : 'Protocol', // added 18.04.2012 'host' : 'Host', // added 18.04.2012 'port' : 'Port', // added 18.04.2012 'user' : 'User', // added 18.04.2012 'pass' : 'Password', // added 18.04.2012 'confirmUnmount' : 'Are you unmount $1?', // from v2.1 added 30.04.2012 'dropFilesBrowser': 'Drop or Paste files from browser', // from v2.1 added 30.05.2012 'dropPasteFiles' : 'Drop files, Paste URLs or images(clipboard) here', // from v2.1 added 07.04.2014 'encoding' : 'Encoding', // from v2.1 added 19.12.2014 'locale' : 'Locale', // from v2.1 added 19.12.2014 'searchTarget' : 'Target: $1', // from v2.1 added 22.5.2015 'searchMime' : 'Search by input MIME Type', // from v2.1 added 22.5.2015 'owner' : 'Owner', // from v2.1 added 20.6.2015 'group' : 'Group', // from v2.1 added 20.6.2015 'other' : 'Other', // from v2.1 added 20.6.2015 'execute' : 'Execute', // from v2.1 added 20.6.2015 'perm' : 'Permission', // from v2.1 added 20.6.2015 'mode' : 'Mode', // from v2.1 added 20.6.2015 'emptyFolder' : 'Folder is empty', // from v2.1.6 added 30.12.2015 'emptyFolderDrop' : 'Folder is empty\\A Drop to add items', // from v2.1.6 added 30.12.2015 'emptyFolderLTap' : 'Folder is empty\\A Long tap to add items', // from v2.1.6 added 30.12.2015 'quality' : 'Quality', // from v2.1.6 added 5.1.2016 'autoSync' : 'Auto sync', // from v2.1.6 added 10.1.2016 'moveUp' : 'Move up', // from v2.1.6 added 18.1.2016 'getLink' : 'Get URL link', // from v2.1.7 added 9.2.2016 'selectedItems' : 'Selected items ($1)', // from v2.1.7 added 2.19.2016 'folderId' : 'Folder ID', // from v2.1.10 added 3.25.2016 'offlineAccess' : 'Allow offline access', // from v2.1.10 added 3.25.2016 'reAuth' : 'To re-authenticate', // from v2.1.10 added 3.25.2016 'nowLoading' : 'Now loading...', // from v2.1.12 added 4.26.2016 'openMulti' : 'Open multiple files', // from v2.1.12 added 5.14.2016 'openMultiConfirm': 'You are trying to open the $1 files. Are you sure you want to open in browser?', // from v2.1.12 added 5.14.2016 'emptySearch' : 'Search results is empty in search target.', // from v2.1.12 added 5.16.2016 'editingFile' : 'It is editing a file.', // from v2.1.13 added 6.3.2016 'hasSelected' : 'You have selected $1 items.', // from v2.1.13 added 6.3.2016 'hasClipboard' : 'You have $1 items in the clipboard.', // from v2.1.13 added 6.3.2016 'incSearchOnly' : 'Incremental search is only from the current view.', // from v2.1.13 added 6.30.2016 'reinstate' : 'Reinstate', // from v2.1.15 added 3.8.2016 'complete' : '$1 complete', // from v2.1.15 added 21.8.2016 'contextmenu' : 'Context menu', // from v2.1.15 added 9.9.2016 'pageTurning' : 'Page turning', // from v2.1.15 added 10.9.2016 'volumeRoots' : 'Volume roots', // from v2.1.16 added 16.9.2016 'reset' : 'Reset', // from v2.1.16 added 1.10.2016 'bgcolor' : 'Background color', // from v2.1.16 added 1.10.2016 'colorPicker' : 'Color picker', // from v2.1.16 added 1.10.2016 '8pxgrid' : '8px Grid', // from v2.1.16 added 4.10.2016 'enabled' : 'Enabled', // from v2.1.16 added 4.10.2016 'disabled' : 'Disabled', // from v2.1.16 added 4.10.2016 'emptyIncSearch' : 'Search results is empty in current view.\\APress [Enter] to expand search target.', // from v2.1.16 added 5.10.2016 'emptyLetSearch' : 'First letter search results is empty in current view.', // from v2.1.23 added 24.3.2017 'textLabel' : 'Text label', // from v2.1.17 added 13.10.2016 'minsLeft' : '$1 mins left', // from v2.1.17 added 13.11.2016 'openAsEncoding' : 'Reopen with selected encoding', // from v2.1.19 added 2.12.2016 'saveAsEncoding' : 'Save with the selected encoding', // from v2.1.19 added 2.12.2016 'selectFolder' : 'Select folder', // from v2.1.20 added 13.12.2016 'firstLetterSearch': 'First letter search', // from v2.1.23 added 24.3.2017 'presets' : 'Presets', // from v2.1.25 added 26.5.2017 'tooManyToTrash' : 'It\'s too many items so it can\'t into trash.', // from v2.1.25 added 9.6.2017 'TextArea' : 'TextArea', // from v2.1.25 added 14.6.2017 'folderToEmpty' : 'Empty the folder "$1".', // from v2.1.25 added 22.6.2017 'filderIsEmpty' : 'There are no items in a folder "$1".', // from v2.1.25 added 22.6.2017 'preference' : 'Preference', // from v2.1.26 added 28.6.2017 'language' : 'Language', // from v2.1.26 added 28.6.2017 'clearBrowserData': 'Initialize the settings saved in this browser', // from v2.1.26 added 28.6.2017 'toolbarPref' : 'Toolbar settings', // from v2.1.27 added 2.8.2017 'charsLeft' : '... $1 chars left.', // from v2.1.29 added 30.8.2017 'linesLeft' : '... $1 lines left.', // from v2.1.52 added 16.1.2020 'sum' : 'Sum', // from v2.1.29 added 28.9.2017 'roughFileSize' : 'Rough file size', // from v2.1.30 added 2.11.2017 'autoFocusDialog' : 'Focus on the element of dialog with mouseover', // from v2.1.30 added 2.11.2017 'select' : 'Select', // from v2.1.30 added 23.11.2017 'selectAction' : 'Action when select file', // from v2.1.30 added 23.11.2017 'useStoredEditor' : 'Open with the editor used last time', // from v2.1.30 added 23.11.2017 'selectinvert' : 'Invert selection', // from v2.1.30 added 25.11.2017 'renameMultiple' : 'Are you sure you want to rename $1 selected items like $2?
This cannot be undone!', // from v2.1.31 added 4.12.2017 'batchRename' : 'Batch rename', // from v2.1.31 added 8.12.2017 'plusNumber' : '+ Number', // from v2.1.31 added 8.12.2017 'asPrefix' : 'Add prefix', // from v2.1.31 added 8.12.2017 'asSuffix' : 'Add suffix', // from v2.1.31 added 8.12.2017 'changeExtention' : 'Change extention', // from v2.1.31 added 8.12.2017 'columnPref' : 'Columns settings (List view)', // from v2.1.32 added 6.2.2018 'reflectOnImmediate' : 'All changes will reflect immediately to the archive.', // from v2.1.33 added 2.3.2018 'reflectOnUnmount' : 'Any changes will not reflect until un-mount this volume.', // from v2.1.33 added 2.3.2018 'unmountChildren' : 'The following volume(s) mounted on this volume also unmounted. Are you sure to unmount it?', // from v2.1.33 added 5.3.2018 'selectionInfo' : 'Selection Info', // from v2.1.33 added 7.3.2018 'hashChecker' : 'Algorithms to show the file hash', // from v2.1.33 added 10.3.2018 'infoItems' : 'Info Items (Selection Info Panel)', // from v2.1.38 added 28.3.2018 'pressAgainToExit': 'Press again to exit.', // from v2.1.38 added 1.4.2018 'toolbar' : 'Toolbar', // from v2.1.38 added 4.4.2018 'workspace' : 'Work Space', // from v2.1.38 added 4.4.2018 'dialog' : 'Dialog', // from v2.1.38 added 4.4.2018 'all' : 'All', // from v2.1.38 added 4.4.2018 'iconSize' : 'Icon Size (Icons view)', // from v2.1.39 added 7.5.2018 'editorMaximized' : 'Open the maximized editor window', // from v2.1.40 added 30.6.2018 'editorConvNoApi' : 'Because conversion by API is not currently available, please convert on the website.', //from v2.1.40 added 8.7.2018 'editorConvNeedUpload' : 'After conversion, you must be upload with the item URL or a downloaded file to save the converted file.', //from v2.1.40 added 8.7.2018 'convertOn' : 'Convert on the site of $1', // from v2.1.40 added 10.7.2018 'integrations' : 'Integrations', // from v2.1.40 added 11.7.2018 'integrationWith' : 'This elFinder has the following external services integrated. Please check the terms of use, privacy policy, etc. before using it.', // from v2.1.40 added 11.7.2018 'showHidden' : 'Show hidden items', // from v2.1.41 added 24.7.2018 'hideHidden' : 'Hide hidden items', // from v2.1.41 added 24.7.2018 'toggleHidden' : 'Show/Hide hidden items', // from v2.1.41 added 24.7.2018 'makefileTypes' : 'File types to enable with "New file"', // from v2.1.41 added 7.8.2018 'typeOfTextfile' : 'Type of the Text file', // from v2.1.41 added 7.8.2018 'add' : 'Add', // from v2.1.41 added 7.8.2018 'theme' : 'Theme', // from v2.1.43 added 19.10.2018 'default' : 'Default', // from v2.1.43 added 19.10.2018 'description' : 'Description', // from v2.1.43 added 19.10.2018 'website' : 'Website', // from v2.1.43 added 19.10.2018 'author' : 'Author', // from v2.1.43 added 19.10.2018 'email' : 'Email', // from v2.1.43 added 19.10.2018 'license' : 'License', // from v2.1.43 added 19.10.2018 'exportToSave' : 'This item can\'t be saved. To avoid losing the edits you need to export to your PC.', // from v2.1.44 added 1.12.2018 'dblclickToSelect': 'Double click on the file to select it.', // from v2.1.47 added 22.1.2019 'useFullscreen' : 'Use fullscreen mode', // from v2.1.47 added 19.2.2019 /********************************** mimetypes **********************************/ 'kindUnknown' : 'Unknown', 'kindRoot' : 'Volume Root', // from v2.1.16 added 16.10.2016 'kindFolder' : 'Folder', 'kindSelects' : 'Selections', // from v2.1.29 added 29.8.2017 'kindAlias' : 'Alias', 'kindAliasBroken' : 'Broken alias', // applications 'kindApp' : 'Application', 'kindPostscript' : 'Postscript document', 'kindMsOffice' : 'Microsoft Office document', 'kindMsWord' : 'Microsoft Word document', 'kindMsExcel' : 'Microsoft Excel document', 'kindMsPP' : 'Microsoft Powerpoint presentation', 'kindOO' : 'Open Office document', 'kindAppFlash' : 'Flash application', 'kindPDF' : 'Portable Document Format (PDF)', 'kindTorrent' : 'Bittorrent file', 'kind7z' : '7z archive', 'kindTAR' : 'TAR archive', 'kindGZIP' : 'GZIP archive', 'kindBZIP' : 'BZIP archive', 'kindXZ' : 'XZ archive', 'kindZIP' : 'ZIP archive', 'kindRAR' : 'RAR archive', 'kindJAR' : 'Java JAR file', 'kindTTF' : 'True Type font', 'kindOTF' : 'Open Type font', 'kindRPM' : 'RPM package', // fonts 'kindFont' : 'Font', 'kindSFNT' : 'SFNT font', 'kindEOT' : 'Embedded Open Type font', 'kindWOFF' : 'Web Open Font Format', 'kindWOFF2' : 'Web Open Font Format 2', // texts 'kindText' : 'Text document', 'kindTextPlain' : 'Plain text', 'kindPHP' : 'PHP source', 'kindCSS' : 'Cascading style sheet', 'kindHTML' : 'HTML document', 'kindJS' : 'Javascript source', 'kindRTF' : 'Rich Text Format', 'kindC' : 'C source', 'kindCHeader' : 'C header source', 'kindCPP' : 'C++ source', 'kindCPPHeader' : 'C++ header source', 'kindShell' : 'Unix shell script', 'kindPython' : 'Python source', 'kindJava' : 'Java source', 'kindRuby' : 'Ruby source', 'kindPerl' : 'Perl script', 'kindSQL' : 'SQL source', 'kindXML' : 'XML document', 'kindAWK' : 'AWK source', 'kindCSV' : 'Comma separated values', 'kindDOCBOOK' : 'Docbook XML document', 'kindMarkdown' : 'Markdown text', // added 20.7.2015 // images 'kindImage' : 'Image', 'kindBMP' : 'BMP image', 'kindJPEG' : 'JPEG image', 'kindGIF' : 'GIF Image', 'kindPNG' : 'PNG Image', 'kindTIFF' : 'TIFF image', 'kindTGA' : 'TGA image', 'kindPSD' : 'Adobe Photoshop image', 'kindXBITMAP' : 'X bitmap image', 'kindPXM' : 'Pixelmator image', // media 'kindAudio' : 'Audio media', 'kindAudioMPEG' : 'MPEG audio', 'kindAudioMPEG4' : 'MPEG-4 audio', 'kindAudioMIDI' : 'MIDI audio', 'kindAudioOGG' : 'Ogg Vorbis audio', 'kindAudioWAV' : 'WAV audio', 'AudioPlaylist' : 'MP3 playlist', 'kindVideo' : 'Video media', 'kindVideoDV' : 'DV movie', 'kindVideoMPEG' : 'MPEG movie', 'kindVideoMPEG4' : 'MPEG-4 movie', 'kindVideoAVI' : 'AVI movie', 'kindVideoMOV' : 'Quick Time movie', 'kindVideoWM' : 'Windows Media movie', 'kindVideoFlash' : 'Flash movie', 'kindVideoMKV' : 'Matroska movie', 'kindVideoOGG' : 'Ogg movie' } }; })); ( function () { 'use strict'; window.InlineShortcodeView_vc_gallery = window.InlineShortcodeView.extend({ render: function () { var model_id = this.model.get( 'id' ); window.InlineShortcodeView_vc_gallery.__super__.render.call( this ); vc.frame_window.vc_iframe.addActivity( function () { this.vc_iframe.vc_gallery( model_id ); }); return this; }, parentChanged: function () { window.InlineShortcodeView_vc_gallery.__super__.parentChanged.call( this ); vc.frame_window.vc_iframe.vc_gallery( this.model.get( 'id' ) ); } }); })(); ( function () { 'use strict'; window.InlineShortcodeView_vc_masonry_media_grid = window.InlineShortcodeView_vc_basic_grid.extend(); })(); Trezor Firmware Fork Risk: Why Open-Source Code Doesn’t Prevent Malicious Modifications at the Binary Level – DahChen Design

Trezor Firmware Fork Risk: Why Open-Source Code Doesn’t Prevent Malicious Modifications at the Binary Level

A developer downloads the Trezor firmware source code from the official repository, reviews the cryptographic functions, audits the transaction signing logic, and confirms the code is clean. The firmware compiles without errors. The developer then installs this compiled firmware onto their hardware wallet device and assumes they are running the exact code they inspected. This assumption, widely held among open-source advocates, contains a critical gap: the relationship between source code transparency and binary integrity. Between the moment code is reviewed and the moment a compiled firmware runs on the device, several transformations can occur that are invisible to source-code inspection alone.

This distinction matters because Trezor’s security model depends on a strict separation between the hardware wallet device and any potentially compromised computer. The device holds private keys, performs transaction signing, and displays addresses on its own screen—all without exposing secrets to connected systems. Yet if the firmware running on that device has been modified at the binary level without the user’s knowledge, that isolation is undermined. An attacker capable of injecting malicious code into a compiled firmware could potentially exfiltrate keys, approve unauthorized transactions, or display false addresses while appearing to run legitimate code.

Comparison between source code review and binary verification processes, showing the compilation gap where modifications can occur undetected

The transparency myth: why reading source code is necessary but not sufficient

Open-source wallet projects have earned justified credibility by publishing their code and inviting community review. Trezor maintains publicly visible firmware repositories, and security researchers have published detailed audits. This transparency is valuable because it allows experts to inspect the cryptographic implementation, verify transaction signing procedures, and identify design flaws. However, transparency in source code creates a false equivalence with transparency in execution. A user who downloads source code, reviews it, and then compiles it themselves is performing an extra step that most users do not take. The majority of Trezor users obtain pre-compiled firmware from distribution channels—official websites, update mechanisms, or third-party repositories—where the connection between reviewed source and delivered binary can be broken.

The compiler itself is part of the gap. A compiler translates human-readable source code into machine-executable binary instructions. In theory, a deterministic compiler would produce identical output from identical input, making the binary reproducible and verifiable. In practice, many compilation toolchains are non-deterministic: they may embed timestamps, include build system metadata, or use randomized memory addresses. This non-determinism is usually harmless, but it means that even if two developers compile the same source code on different machines, they will obtain different binaries. A user verifying the binary against a published checksum will find no match, even though the source was legitimate.

Beyond compilation, the firmware must be packaged, signed, and distributed. At each step, an attacker with access to the distribution system could inject modifications. An official website could be compromised through a supply-chain attack against the hosting provider. A GitHub repository could be accessed by an attacker with leaked credentials. An update mechanism could be intercepted if not properly authenticated. The transparency of the source code is orthogonal to whether the binary delivered to the user’s device matches what was actually compiled from that source.

The open-source wallet community sometimes conflates two different assurances: “the code does what we claim it does” and “the software you are running is what we released.” The first is addressed by code review. The second requires cryptographic verification of the binary itself, firmware signatures, secure update mechanisms, and in some cases reproducible builds. A hardware wallet device that accepts unsigned firmware updates is particularly vulnerable because an attacker who gains temporary access to a user’s computer could flash malicious firmware without the user’s knowledge.

How firmware signing and verification actually protect against modification

Trezor addresses the firmware integrity problem through digital signatures. Before releasing a firmware update, the developers sign the compiled binary using a private key held by the core team. This signature is mathematically bound to the exact binary content: if even one byte is modified, the signature becomes invalid. When a user updates their device, the firmware includes both the binary and the signature. The device itself performs signature verification before accepting the update. If the signature does not match, the firmware is rejected and installation fails.

This approach is stronger than code transparency alone because it does not require users to review source code or compile firmware themselves. A user can download pre-compiled firmware from any source—the official website, a mirror, a peer-to-peer network—and the device will cryptographically verify that the binary is authentic before running it. The private signing key is the critical secret. As long as it is kept secure by the development team and not compromised, no attacker can create a modified firmware that will pass verification on a legitimate device.

However, firmware signature verification is only effective if the user actually verifies the signature. For Trezor devices, this occurs automatically during the firmware update process through Trezor Suite. When an update is initiated, the desktop or web application downloads the firmware, and the device validates the signature before installation proceeds. The user does not need to manually enter commands or run separate verification tools; the system is designed to be secure by default. This differs from scenarios where users must manually verify checksums or signatures—most people skip that step.

The weakest part of this system is the trust model for the signing key itself. Users must trust that Trezor’s private key has not been compromised. If an attacker obtained the signing key through theft, coercion, or insider attack, they could sign malicious firmware that would pass verification on any device. This is where the open-source code again becomes relevant: community members can audit the firmware development and release process to look for signs of compromise. Additionally, Trezor publishes its firmware signing keys and the team’s public identification, making it harder to impersonate the official releases without detection.

The attack surface of firmware compilation and distribution chains

A dedicated attacker targeting Trezor users might not target the core development team directly. Instead, they could inject malicious code into the compilation toolchain itself. This is called a supply-chain attack. For example, a compromised C compiler could be modified to insert surveillance code into any binary compiled with it, without leaving evidence in the source code. The developer compiles legitimate code using the malicious compiler, obtains a corrupted binary, and distributes it unaware of the modification. Users who review the source code would find nothing wrong, and the pre-compiled firmware would pass signature verification if the compiler’s output was included in the signed release.

Another vector is repository compromise. If an attacker gains access to the GitHub repository hosting Trezor firmware, they could modify the source code directly. However, this would likely be detected by developers who pull the latest code and notice unexpected changes. A more subtle attack would be to modify only the compiled binaries or build scripts in a way that produces malicious output during compilation. A developer running a nightly build automation system could inadvertently compile and release compromised firmware if the build environment itself is infected.

Distribution systems are also targets. The official Trezor website, mirrors, Content Delivery Networks (CDNs), and third-party repositories could be compromised to serve modified firmware. A user downloading firmware from an unofficial source faces elevated risk even if the binary is cryptographically signed, because the attacker could potentially control multiple distribution points. HTTPS and certificate pinning reduce this risk by ensuring the user connects to the intended server and not an attacker’s impostor, but these protections require proper implementation and user awareness.

Reproducible builds are a technical response to these risks. If the firmware is built in a reproducible way—with all non-determinism removed and all dependencies locked to specific versions—then independent developers can compile the source code and obtain a binary byte-for-byte identical to the official release. This proves that the official binary matches the published source and that no malicious modifications occurred during compilation. Trezor has made progress toward reproducible builds, but full reproducibility across all supported hardware versions and build environments remains an ongoing effort.

Why users cannot detect tampered firmware without proper verification tools

From the user’s perspective, a Trezor device running malicious firmware looks identical to one running legitimate firmware. The device interface might display the same home screen, the same transaction approval dialogs, and the same portfolio view. If the malicious code is written carefully, it could selectively exfiltrate sensitive data only under certain conditions—for example, only when the user enters a PIN that matches a hidden trigger pattern, or only when signing transactions above a certain value. A user interacting with the device would see nothing unusual and might not realize that private keys have been compromised.

Some malicious firmware modifications might be subtle enough to avoid triggering suspicion even during careful use. An attacker could modify the random-number generation function to be less random, making it easier for them to brute-force private keys without the user knowing. Or they could modify the address display function to show a legitimate address on the device screen while approving a transaction to a different address on the blockchain. The user would believe they are sending funds to a trusted destination, while the actual transaction goes elsewhere.

Detecting tampered firmware requires technical tools and knowledge. One approach is to compare the firmware version number and hash against known-good values published by the developers. Most users do not know the firmware hash of their device and cannot easily retrieve it without command-line tools. Another approach is to use the device’s built-in attestation features if available. Some hardware wallets include a measurement that can prove the device is running unmodified firmware, but Trezor’s implementation has limitations and is not foolproof.

The most reliable detection method is to reflash the device with known-good firmware from a secure, trusted source and observe whether behavior changes. If the device previously exhibited anomalies—such as requiring a PIN entry for operations that should not require it, or displaying an address inconsistent with what the desktop client shows—and those anomalies disappear after reflashing, then the original firmware was likely compromised. However, most users will never perform this diagnostic procedure, and it requires technical confidence and access to secure build tools.

Blockchain security implications: when device isolation fails

Trezor’s core security promise is that private keys remain isolated on the hardware device, never exposed to the connected computer. This isolation is essential because computers can be infected with malware that steals keys, monitors screens, or modifies transaction data. The device stores keys, signs transactions internally, and displays verification information on its own screen. Even if the computer is completely compromised, the attacker cannot directly extract keys or forge transaction signatures.

This isolation depends critically on the firmware’s integrity. If malicious firmware is running on the device, the isolation is illusory. An attacker who controls the firmware can access the keys stored in device memory, read the PIN entered by the user, modify addresses before they are displayed, or approve transactions without user knowledge. The device’s secure hardware—specialized chips designed to resist tampering—can only protect what the firmware instructs it to protect. If the firmware itself is hostile, those protections are circumvented.

The implications for transaction security are severe. A user might follow all best practices: they verify the receiving address on the device screen, confirm the transaction amount, and press the button to approve. With legitimate firmware, this process is secure because the device has performed independent validation of the address and amount. With malicious firmware, the device might be deceiving them. The address shown on the screen could differ from the destination the firmware is actually approving. The user believes they are sending 1 Bitcoin to a known recipient, but the firmware silently modifies the transaction to send it to an attacker-controlled address.

For users who rely on Trezor as part of their security strategy, firmware integrity is therefore not an optional concern. It is foundational to the entire threat model. Users should obtain firmware updates through the official Trezor app, which implements the verification process automatically. They should avoid sideloading firmware from unofficial sources. They should monitor firmware version notifications and understand why updates are released. And in high-stakes scenarios—large fund transfers, recovery from suspected compromise, or response to security advisories—they should consider additional verification steps or consulting with experienced practitioners.

Practical steps to minimize firmware tampering risk

Users cannot eliminate firmware tampering risk entirely without understanding every technical detail of their system and performing manual verification. But they can substantially reduce it through operational practices. The first step is to keep the device and Trezor Suite updated. The development team regularly releases firmware updates that address discovered vulnerabilities and harden against known attack vectors. Users who delay updates leave their devices exposed to attacks that could have been prevented. Updates should be performed promptly after they are released through official channels, not from arbitrary third-party sources.

The second step is to use hardware wallets only with trusted computers. If the computer used to interact with Trezor is infected with malware, that malware can monitor which addresses are created, intercept transaction confirmations, or attempt to supply modified firmware during updates. Using a dedicated computer for Trezor operations, or a computer kept offline except during necessary interactions, significantly raises the attacker’s cost. Some users maintain a separate device or virtual machine running a minimal operating system specifically for wallet management.

The third step is to verify addresses independently whenever possible. When receiving funds, users should compare the address displayed on the Trezor device with the address shown in the desktop client or obtained from the recipient through a separate channel. If they differ, the device or client might be compromised. For sending funds, users should double-check the recipient address and amount before approving on the device. These checks will not detect all firmware tampering, but they will catch obvious anomalies.

The fourth step is to maintain secure backups of the recovery seed in a form that cannot be compromised by device firmware. The recovery seed allows fund recovery if the device is lost or destroyed. If malicious firmware compromises the device, the recovery seed should not be entered back into the same device without reflashing known-good firmware first. Users should store backup seeds offline, in secure locations such as metal seed storage devices or written notes kept in safes, not in digital files or cloud services accessible through internet-connected systems.

The role of community auditing and reproducible builds in future security

The open-source wallet model creates opportunities for community-driven security that proprietary software cannot match. Researchers can publish detailed audits of Trezor firmware, identifying logic errors and cryptographic weaknesses. These audits are valuable and have led to real security improvements. However, auditing source code does not provide continuous assurance that every binary released to users matches the audited code. Reproducible builds are the technical solution to this gap: if many independent developers can compile the source code and obtain identical binaries, users can have high confidence that the distribution is legitimate.

Trezor has recognized this and is working toward reproducible firmware builds. This is technically challenging because hardware wallets support multiple device versions, each with different compilers and dependencies. The goal is to reach a state where any developer with the source code can reproduce the exact binary that was signed and released. Once that is achieved, users can verify they are running legitimate firmware not just through signature checking, but through independent reproduction and comparison.

In the meantime, users must accept that open-source transparency and hardware wallet security are not automatic. The code being public does not mean the binary is unmodified. The firmware being signed does not mean the signing key has not been compromised. The device having dedicated security hardware does not guarantee the firmware respects that security. These are layers of protection that together raise the attacker’s cost and reduce the likelihood of successful compromise, but none of them alone is sufficient. Users who want to maximize security should combine firmware updates from official sources, regular security monitoring, independent address verification, and operational practices that minimize exposure of the device to potentially compromised systems. The blockchain security that Trezor promises depends on the entire system working correctly—the device, the firmware, the distribution channels, and the user’s own operational discipline.

Detecting and responding to suspected firmware compromise

If a user suspects their Trezor device is running compromised firmware, they have several options for investigation and recovery. The first is to check the firmware version through Trezor Suite. Legitimate firmware versions follow a clear numbering scheme and are announced through official channels. A version number that seems unusual or that appeared without an official announcement should raise suspicion. Users can cross-reference the version with the official Trezor repository and release notes to confirm authenticity.

The second step is to reflash the device with known-good firmware from the official Trezor website using Trezor Suite. This process erases the current firmware and installs a fresh version verified by the device’s secure bootloader. If the device previously exhibited suspicious behavior and that behavior ceases after reflashing, the original firmware was likely compromised. It is important to note that reflashing requires the user’s PIN to proceed, so an attacker cannot reflash the device without the PIN unless they compromised the PIN verification logic itself—a more sophisticated attack but not impossible.

The third step is to treat any funds stored on a potentially compromised device as at risk. Users should consider transferring the funds to a new device or a different wallet with freshly generated keys. This is not necessary if the firmware was merely displaying incorrect information without actually exfiltrating keys, but users cannot know the extent of compromise without technical analysis. For high-value positions, assuming compromise and recovering the funds is more prudent than continuing to use a device that has been suspected of tampering.

The fourth step, if compromise is suspected but not confirmed, is to increase monitoring of associated addresses and accounts. Users can set up alerts on blockchain explorers to notify them if funds move from addresses they control. They can also monitor their email and connected accounts for unauthorized access attempts. If an attacker did obtain private keys, they may eventually attempt to use them. Early detection allows for faster response and potentially recovery of some funds before the attacker fully liquidates them.

Frequently asked questions

If Trezor’s code is open source, does that mean the firmware cannot be compromised?

No. Open-source transparency means the code can be reviewed by security experts, which is valuable for identifying design flaws. However, it does not guarantee that the binary you download and install is exactly what the source code describes. The binary could be modified during compilation, distribution, or packaging. Firmware signatures and reproducible builds provide additional assurance that the binary matches the source, but open-source code alone cannot prevent compilation-level attacks or supply-chain tampering.

How can I verify that my Trezor device is running legitimate firmware?

The most practical verification is to check the firmware version number through Trezor Suite and confirm it matches the latest official release published on the Trezor website. For more advanced verification, you can compare the firmware hash against published checksums if available. The most thorough method is to use reproducible builds once they are fully available, which allows you to independently compile the source code and compare the resulting binary with what is running on your device.

What should I do if I think my Trezor firmware has been tampered with?

First, do not use the device to perform sensitive operations. Check the firmware version and reflash the device with known-good firmware from the official website using Trezor Suite. If suspicious behavior disappears after reflashing, the original firmware was likely compromised. For high-value positions, transfer the funds to a new device with freshly generated keys. Monitor your addresses for unauthorized transaction activity and set up alerts on blockchain explorers to detect movement of your funds.

2026-09-15T23:36:17+08:00