Home » CZ Says Software Wallets Avoid Risks Seen in Trezor Leak

CZ Says Software Wallets Avoid Risks Seen in Trezor Leak

by Brandon Duncan
0 comments



Security expert Nick Neuman warned that leaked home addresses could enable criminals to more easily target people for wrench attacks.

On August 13, Trezor disclosed that a data breach at its shipping partner, ShipMonk, exposed the personal information of roughly 13,700 recent customers, including names, phone numbers, and home addresses.

Binance founder Changpeng Zhao (CZ) responded by arguing that the incident shows a real advantage of software self-custody wallets, since they don’t require shipping a physical device that ties a buyer’s identity to a home address.

Trezor Breach Puts Physical Addresses in Focus

Trezor disclosed the incident after ShipMonk, a logistics provider, notified the company on Monday, August 10, about unauthorized access to systems holding customer order data.

CZ reacted on Thursday, contending that the incident highlights a different risk profile for hardware and software self-custody.

“Hardware wallets are often considered ‘more secure’ than software wallets,” he wrote. “While I still think that is ‘generally true’ in a few specific aspects, this incident reinforces an advantage of software self-custody wallets.”

He pointed to examples such as Binance Web3 Wallet and Trust Wallet, which do not require shipping a physical device that ties a user’s identity and address to crypto ownership.

CZ also stopped short of dismissing hardware wallets. “Not saying hardware wallets are ‘bad,’” he wrote. “Just different profiles.” He added that YZiLabs is an investor in many hardware wallet companies.

Contributing to the debate, NaoX Protocol said the exposed addresses could give attackers a list of verified crypto holders worth targeting in person. Bitcoin security executive Nick Neuman similarly warned that the data could lead to targeted social engineering and potentially wrench attacks, where criminals use physical threats to steal funds.

You may also like:

Trezor said customers could face more sophisticated phishing through email, phone calls or letters. It urged users never to enter their wallet backup online or share it with anyone.

A Rough Stretch for Hardware Wallets

The timing adds to a run of bad headlines for hardware wallet makers. In mid-July, on-chain investigator ZachXBT called the category unfit for serious use, writing on Telegram that “all hardware wallets are complete garbage.”

He argued a spare phone used only for signing transactions could work better, citing dead batteries, forced firmware updates, and interface bugs as recurring problems. The Trezor breach is a different kind of failure, as it involves exposure through a vendor rather than the device, but it fits the same conversation about costs beyond the seed phrase.

Furthermore, last week, Galaxy Research linked more than $100 million in stolen Bitcoin to a separate issue in older Coldcard firmware, which generated wallet seeds with weaker randomness than intended. Coinkite has patched the flaw in newer releases but cannot fix seeds already generated on affected devices and has told holders of its Mk3 through Q models to move funds to unaffected hardware.

This isn’t the first time Trezor has found itself in such a situation, with a separate breach tied to a third-party support vendor exposing contact details for around 66,000 users in January 2024.



Source link

You may also like

Editor Pics

Latest News

© 2025 blockchainsphere.info. All rights reserved.