Binance founder Changpeng Zhao argues a ShipMonk data breach that exposed Trezor customers' home addresses shows an advantage of software self-custody over hardware wallets. The incident adds to a string of setbacks for hardware wallet makers, including a Coldcard firmware flaw tied to more than $100 million in stolen Bitcoin.
Shipping Data Exposes Trezor Buyers
Trezor disclosed on August 13 that a breach at its shipping partner, ShipMonk, exposed the names, phone numbers, and home addresses of roughly 13,700 recent customers. ShipMonk notified Trezor on Monday, August 10, about unauthorized access to systems holding customer order data.
Changpeng Zhao (CZ) responded on Thursday, arguing the breach highlights a different risk profile for software self-custody wallets, since apps such as Binance Web3 Wallet and Trust Wallet don't require shipping a physical device that ties a buyer's identity to a home address. According to CZ: "this incident reinforces an advantage of software self-custody wallets". He added that he still considers hardware wallets "generally true" to be more secure in a few specific aspects, and noted that YZiLabs is an investor in many hardware wallet companies.
Warnings Over Physical Risk
NaoX Protocol said the exposed addresses could give attackers a list of verified crypto holders worth targeting in person. Bitcoin security executive Nick Neuman similarly warned that the data could lead to targeted social engineering and potentially wrench attacks, where criminals use physical threats to steal funds. Trezor said customers could face more sophisticated phishing through email, phone calls, or letters, and urged users never to enter their wallet backup, or seed phrase, online or share it with anyone.
Part of a Broader Pattern
The disclosure follows a rough stretch for hardware wallet makers. In mid-July, on-chain investigator ZachXBT called the category unfit for serious use, arguing that a spare phone used only for signing transactions could work better than a device prone to dead batteries, forced firmware updates, and interface bugs.
Last week, Galaxy Research linked more than $100 million in stolen Bitcoin to weaker-than-intended randomness in older Coldcard firmware. Coinkite has patched the flaw in newer releases but cannot fix seeds already generated on affected devices, and it has told holders of its Mk3 through Q models to move funds to unaffected hardware. Trezor itself disclosed a separate breach tied to a third-party support vendor that exposed contact details for around 66,000 users in January 2024.
Source: CryptoPotato
Trading involves risk.