In February 2025, Alonso Vidales, a security researcher and senior software engineer at Microsoft, identified a vulnerability in Proton's web interface. This flaw allowed a malicious sender to bypass the email service's alert systems, potentially tricking users into believing they were receiving legitimate emails. Vidales reported the issue to Proton, which confirmed the vulnerability in April 2025 and issued a reward through its Bug Bounty program. Despite this, the vulnerability remains unfixed as of September 30, 2025. Vidales has now decided to publicly disclose the details of his findings, and he successfully reproduced the issue on his own Proton accounts in September 2026. The vulnerability exploits a common typographical trick used in email spoofing. For example, a scammer could replace the lowercase "l" with an uppercase "I" in a domain name like "gmail." In the font used by Proton's web interface on macOS, these characters look identical. While Proton Mail has protections against certain types of homoglyphs—characters that look similar but have different encoding—it does not guard against this basic typographical deception. Additionally, the scammer can include a false address in the "display name" field, which the interface highlights in a way that might mislead users into thinking it is the sender's actual address. At the core of the vulnerability is a lack of alert when there is a mismatch between the technical sender and the domain shown in the "From" field. If the real sender's domain does not publish a DMARC (Domain-based Message Authentication, Reporting, and Conformance) record, Proton Mail does not show a warning, even if the email fails an SPF (Sender Policy Framework) check. For domains with a DMARC record, Proton does display a warning. However, if a domain lacks DMARC, the fraudulent email arrives without any alert. This means a user could reply to a scam email without triggering a warning, even if the scammer has redirected the replies to an address they control. To avoid falling into this trap, users must check the email headers, especially when there is a mismatch between the "From" and "Reply To" fields. Proton, which claims over 100 million users for its email service, has not provided a specific date for a patch. When contacted by the media outlet CyberInsider, the company stated on October 1 that it had no comment at this time. In the meantime, individuals who may have been affected by hacking or data breaches are advised to take steps to protect themselves. These include changing passwords for affected accounts immediately, updating passwords across other services, using unique and strong passwords, enabling two-factor authentication (2FA) where possible, and using passkeys if available. Users should also be cautious of suspicious emails, texts, or calls, avoid clicking on uncertain links or downloading attachments, inform contacts if a breach may affect them, and ensure their devices and software are up to date. In the event of fraudulent transfers, reporting through the Perceval platform is recommended.