CZ Says Trezor Data Breach Highlights Privacy Advantage of Software Self-Custody Wallets
Key Takeaways
- •A breach at one of Trezor's third-party shipping providers exposed the personal information of 11,742 customers fully and 1,947 customers partially.
- •Trezor confirmed that its internal systems and hardware devices were not compromised during the incident.
- •Changpeng Zhao argued that software self-custody wallets offer a privacy advantage because they do not require physical shipping tied to personal details.
- •A similar supply-chain breach at Ledger in 2020 exposed data from approximately 272,000 customers and led to phishing campaigns and extortion attempts.
- •Both hardware and software wallets carry distinct security trade-offs, and users remain responsible for protecting their recovery phrases and private keys regardless of wallet type.

Binance founder Changpeng Zhao (CZ) has commented publicly on the recent Trezor data breach, arguing that the incident underscores a privacy advantage of software-based self-custody wallets over hardware alternatives.
Breach Details
The breach occurred at one of Trezor's third-party shipping providers and exposed personal information belonging to Trezor customers. According to the company, 11,742 customers were fully affected, while an additional 1,947 customers had partial information exposed. Trezor emphasized that its own internal systems and hardware devices remained secure throughout the incident.
The Trezor incident is not the first time a major hardware wallet manufacturer has faced a customer data exposure tied to its supply chain. In 2020, competitor Ledger suffered a data breach that compromised the personal information of roughly 272,000 customers, including names, phone numbers, and shipping addresses. That earlier incident led to widespread phishing campaigns and physical extortion attempts targeting Ledger customers, illustrating the real-world consequences when purchasing data is compromised.
CZ Highlights Software Wallet Privacy Benefit
In his remarks on the breach, Zhao pointed to a key distinction between hardware and software self-custody. Purchasing a physical hardware wallet often requires customers to provide personal details such as a name, phone number, and delivery address. This creates a data trail outside the wallet itself — information that could potentially be exposed if a retailer, logistics company, or other third party suffers a security breach.
Software self-custody wallets, by contrast, can be downloaded and installed without any physical shipment, eliminating the delivery-related data trail that Zhao identified as a privacy concern.
NEW: Binance founder CZ weighs in on the Trezor data breach, noting it reinforces an advantage of software self-custody wallets. Unlike hardware wallets, they don't require a physical device tied to your identity and shipping address. pic.twitter.com/xqg1X083lt
— Cointelegraph (@Cointelegraph) August 14, 2026
Broader Security and Privacy Considerations
Zhao's observation does not imply that software wallets are inherently safer overall. Hardware and software wallets each carry distinct security and privacy trade-offs. Hardware wallets are specifically designed to keep private keys isolated from internet-connected devices, reducing exposure to online threats such as malware and phishing-based key theft. However, the purchasing process for physical devices can introduce separate privacy risks through third-party services involved in order fulfillment and shipping.
Regardless of wallet type, users remain responsible for safeguarding their recovery phrases and private keys.
The Trezor incident has drawn attention to a broader issue within crypto self-custody: the need to protect not only digital assets but also the personal information collected and stored throughout the purchasing process. The recurrence of supply-chain data breaches at major hardware wallet vendors may prompt both manufacturers and customers to reconsider how purchasing data is minimized, stored, and protected — alongside the ongoing security of the hardware devices themselves.