pull down to refresh

Trezor's shipping partner ShipMonk leaked 13,700 customers' names, phone numbers and home addresses. Zero coins lost. Keys untouched. It's a logistics vendor with sloppy access, not a wallet failure.

CZ jumped in and called it proof that software self-custody is better, then plugged Binance Web3 Wallet and Trust Wallet. The two wallets in his own house.

He's got half a point buried in there. Buying a hardware wallet does put your name and address on a shipping label, and that label just became a phishing list. Fair.

But a hot wallet's seed sits on a networked device. One piece of malware and you're drained while you sleep. The Trezor leak didn't touch a single key. It exposed mail and addresses because a middleman kept data it shouldn't have.

Meanwhile the real hardware story this week is Coldcard's weak seed randomness on older firmware. Galaxy Research puts the damage north of a hundred million, and Coinkite can't fix seeds already generated. That's a firmware problem. CZ left that part out.

So no, the lesson isn't that hot wallets are fine. Don't let a middleman hold your data, keep your firmware auditable and current. A shipping leak and a firmware bug don't make a hot wallet the answer.

https://x.com/cz_binance/status/2087971745190044010