Trezor's shipping partner ShipMonk leaked 13,700 customers' names, phone numbers and home addresses. Zero coins lost. Keys untouched. It's a logistics vendor with sloppy access, not a wallet failure.
CZ jumped in and called it proof that software self-custody is better, then plugged Binance Web3 Wallet and Trust Wallet. The two wallets in his own house.
He's got half a point buried in there. Buying a hardware wallet does put your name and address on a shipping label, and that label just became a phishing list. Fair.
But a hot wallet's seed sits on a networked device. One piece of malware and you're drained while you sleep. The Trezor leak didn't touch a single key. It exposed mail and addresses because a middleman kept data it shouldn't have.
Meanwhile the real hardware story this week is Coldcard's weak seed randomness on older firmware. Galaxy Research puts the damage north of a hundred million, and Coinkite can't fix seeds already generated. That's a firmware problem. CZ left that part out.
So no, the lesson isn't that hot wallets are fine. Don't let a middleman hold your data, keep your firmware auditable and current. A shipping leak and a firmware bug don't make a hot wallet the answer.
https://x.com/cz_binance/status/2087971745190044010
https://twiiit.com/cz_binance/status/2087971745190044010