CZ points to Trezor breach as an argument for software self-custody wallets
Binance founder CZ used the ShipMonk data breach affecting 11,742 Trezor customers to argue that buying a physical hardware wallet links a user's identity and address to their crypto holdings, naming Binance Web3 Wallet and Trust Wallet as lower-risk alternatives.
Binance founder @cz_binance has used a data breach at Trezor's shipping provider as fresh ammunition in his argument for software-based self-custody wallets, saying the act of purchasing and receiving a physical device creates a paper trail that links a buyer's real-world identity and home address to their crypto holdings.
Writing on X, @cz_binance named Binance Web3 Wallet and @TrustWallet as alternatives that avoid that specific exposure. He also disclosed that @yzilabs invests in a number of hardware wallet companies, framing the debate as a matter of different risk profiles rather than a categorical verdict against cold storage.
What happened at ShipMonk
The breach that prompted the remarks was confirmed by Trezor on August 13, 2026. According to BleepingComputer, Trezor's shipping provider ShipMonk notified the company on August 10 that an unauthorized party had accessed its systems. The incident affected 11,742 customers whose full names, email addresses, phone numbers, and shipping addresses were exposed, along with a further 1,947 customers who suffered partial exposure of name, city, and email. Trezor itself said it was the first breach in the company's history to expose customer phone numbers and shipping addresses.
ShipMonk told affected customers that the attackers exploited a vulnerability in the third-party analytics platform Metabase. Trezor confirmed that its own infrastructure, firmware, and devices were not compromised. Affected customers covered orders placed between May 10 and August 8, 2026, across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
Broader context for hardware wallet security
The Trezor incident follows a difficult stretch for hardware wallet makers. In late July, a firmware flaw in Coldcard Mk3 devices dating to March 2021 was exploited to drain approximately 1,082 $BTC, worth around $70 million at the time, in a window of roughly 41 minutes. CoinDesk reported that @cz_binance responded to that incident by urging holders to split funds across multiple wallets, while cautioning that even that approach carries its own risks and that nothing is 100 percent safe.
The ShipMonk breach adds a different dimension to the hardware wallet risk discussion: the supply chain and logistics layer, not just firmware. Trezor said it plans to introduce an anonymous delivery option featuring locker pickup, neutral packaging, and automatic deletion of shipping identifiers, targeting European customers by September 2026 and US customers by year-end. Affected customers are advised to treat unexpected contact with suspicion and to never enter a wallet backup online.
Sources:
BleepingComputer: Trezor discloses data breach affecting nearly 14,000 customers
Trezor: Recent customer data exposed in shipping provider incident
CoinDesk: Binance founder CZ calls for wallet diversification after Coldcard exploit
Latest News
Read More...
Author
Crypto RichRich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.













