The Weekly Brief · August 16, 2026

Phishing Moved Offline This Week: Postal Letters Started Arriving in Switzerland

The threat surface expanded beyond email and Discord this week. A physical-letter campaign and an impersonator app both targeted the same Trezor-shipper breach data.

About this brief

Editor: Bithues Editorial Desk. The desk tracks digital-asset custody, exchange, and threat stories for Bitcoin and Ethereum holders and operators; editorial standards and review process are documented in the research archive.

Launched: Bithues went live in as an editorial desk covering the custody, exchange, and threat stories behind Bitcoin and Ethereum for holders and operators.

Editorial process: Each weekly brief distils primary reporting (court filings, regulatory notices, on-chain confirmation) into a worked-example frame: what happened, why it matters, what to do this week. Items are screened against the research archive and cross-checked against at least one confirming source before publication.

Corrections policy: When a brief gets a fact wrong, we correct it inline and append a dated correction note at the top of the next brief. Send corrections to the editor.

Disclosure: Bithues does not provide trading signals, price calls, or financial advice. The desk may hold the assets mentioned in a brief; positions are disclosed at the time of writing. Affiliate links, where present, are tagged rel="sponsored".

This week's signal

Why it matters

  • Physical mail bypasses every spam filter and most users' threat models. A letter referencing a real wallet order, a real address, and a real purchase history is qualitatively different from an email — most users do not have a mental model for 'this is a phishing letter.'
  • App-store impersonation bypasses the 'I downloaded it from the official store' assumption that most users treat as a safety signal. The fact that the app made it through review proves that store-trust is not a defense.
  • The Trezor breach data set (last week) is now being actively weaponized. The lag between breach disclosure and phishing-wave launch is days, not months.
  • The 'verify by clicking through' guidance no longer applies when the phishing message references a real address and looks like a real letter. The correct verification path is to open the vendor's site yourself and call their published support number.

What to do this week

    Key developments

    Physical letters demanding 'Post-Quantum Cryptography Security Updates' arrived at Swiss homes this week

    High
    What happened
    BACS, the Swiss banking standards body, responded to reports of physical letters arriving at homes demanding a 'Post-Quantum Cryptography Security Update' with a deadline. The letters use the corporate branding of a major hardware-wallet vendor and reference real shipping addresses.
    Why it matters
    Physical mail bypasses every spam filter and most users' threat models. The phishing channel expanded this week in ways that standard operational-security checklists do not cover.
    Reader implication
    Treat any physical letter about a wallet as hostile by default. Verify by calling the vendor's published support number (from their official site), not by responding to the letter.
    • phishing
    • operational security
    • supply-chain attack

    Fieldfisher: How the Coldcard attack actually unfolded, hour by hour

    Critical
    What happened
    Fieldfisher's deep dive on the attack timeline: first sweep began at 01:31 UTC on July 30, ~594 BTC vanished from ~500 wallets in the first 25 minutes, and the campaign continued in waves. The piece walks victims through what they can and cannot recover.
    Why it matters
    The operational detail of the attack (the speed, the wave structure, the seed-phrase generation flaw) is now the canonical reference for understanding how a generation-step compromise plays out in practice.
    Reader implication
    Anyone who generated a Coldcard seed during the affected window should assume the worst. Move funds to a new seed on a different device, not a new wallet on the same device.
    • firmware risk
    • seed-phrase exposure
    • private-key compromise

    The same whale was drained a third time — this time for $25.6M

    Critical
    What happened
    The same Ethereum whale address that lost $24M in 2023 and $26M earlier this week was drained again — this time through a malicious token approval that emptied WBTC, cbBTC, LDO, USDS, and CRV before the attacker converted to DAI and ETH. Three different mechanisms, one persistent target.
    Why it matters
    The address is the persistent identifier. The attack mechanism rotates. The cure is to break the on-chain link to the address entirely.
    Reader implication
    If your wallet address has been hit before, the address is on a target list. A new seed on the same device does not remove you from the list. A new wallet on a different device with no on-chain link does.
    • approval abuse
    • treasury exposure
    • phishing