The Weekly Brief · August 16, 2026
Phishing Moved Offline This Week: Postal Letters Started Arriving in Switzerland
The threat surface expanded beyond email and Discord this week. A physical-letter campaign and an impersonator app both targeted the same Trezor-shipper breach data.
About this brief
Editor: Bithues Editorial Desk. The desk tracks digital-asset custody, exchange, and threat stories for Bitcoin and Ethereum holders and operators; editorial standards and review process are documented in the research archive.
Launched: Bithues went live in as an editorial desk covering the custody, exchange, and threat stories behind Bitcoin and Ethereum for holders and operators.
Editorial process: Each weekly brief distils primary reporting (court filings, regulatory notices, on-chain confirmation) into a worked-example frame: what happened, why it matters, what to do this week. Items are screened against the research archive and cross-checked against at least one confirming source before publication.
Corrections policy: When a brief gets a fact wrong, we correct it inline and append a dated correction note at the top of the next brief. Send corrections to the editor.
Disclosure: Bithues does not provide trading signals, price calls, or financial advice. The desk may hold the assets mentioned in a brief; positions are disclosed at the time of writing. Affiliate links, where present, are tagged rel="sponsored".
This week's signal
Why it matters
- Physical mail bypasses every spam filter and most users' threat models. A letter referencing a real wallet order, a real address, and a real purchase history is qualitatively different from an email — most users do not have a mental model for 'this is a phishing letter.'
- App-store impersonation bypasses the 'I downloaded it from the official store' assumption that most users treat as a safety signal. The fact that the app made it through review proves that store-trust is not a defense.
- The Trezor breach data set (last week) is now being actively weaponized. The lag between breach disclosure and phishing-wave launch is days, not months.
- The 'verify by clicking through' guidance no longer applies when the phishing message references a real address and looks like a real letter. The correct verification path is to open the vendor's site yourself and call their published support number.
What to do this week
Key developments
Physical letters demanding 'Post-Quantum Cryptography Security Updates' arrived at Swiss homes this week
High- What happened
- BACS, the Swiss banking standards body, responded to reports of physical letters arriving at homes demanding a 'Post-Quantum Cryptography Security Update' with a deadline. The letters use the corporate branding of a major hardware-wallet vendor and reference real shipping addresses.
- Why it matters
- Physical mail bypasses every spam filter and most users' threat models. The phishing channel expanded this week in ways that standard operational-security checklists do not cover.
- Reader implication
- Treat any physical letter about a wallet as hostile by default. Verify by calling the vendor's published support number (from their official site), not by responding to the letter.
- Source · www.zerberos.com https://www.zerberos.com/en/crypto-wallet-phishing-by-mail-when-cybercriminals-use-the-postal-service/
Fieldfisher: How the Coldcard attack actually unfolded, hour by hour
Critical- What happened
- Fieldfisher's deep dive on the attack timeline: first sweep began at 01:31 UTC on July 30, ~594 BTC vanished from ~500 wallets in the first 25 minutes, and the campaign continued in waves. The piece walks victims through what they can and cannot recover.
- Why it matters
- The operational detail of the attack (the speed, the wave structure, the seed-phrase generation flaw) is now the canonical reference for understanding how a generation-step compromise plays out in practice.
- Reader implication
- Anyone who generated a Coldcard seed during the affected window should assume the worst. Move funds to a new seed on a different device, not a new wallet on the same device.
- Source · www.fieldfisher.com https://www.fieldfisher.com/en/insights/coinkite-coldcard-hack-what-victims-need-to-know
The same whale was drained a third time — this time for $25.6M
Critical- What happened
- The same Ethereum whale address that lost $24M in 2023 and $26M earlier this week was drained again — this time through a malicious token approval that emptied WBTC, cbBTC, LDO, USDS, and CRV before the attacker converted to DAI and ETH. Three different mechanisms, one persistent target.
- Why it matters
- The address is the persistent identifier. The attack mechanism rotates. The cure is to break the on-chain link to the address entirely.
- Reader implication
- If your wallet address has been hit before, the address is on a target list. A new seed on the same device does not remove you from the list. A new wallet on a different device with no on-chain link does.
- Source · cryptoadventure.com https://cryptoadventure.com/crypto-whale-drained-of-25-6m-in-second-major-phishing-attack/
- Also reported by · crypto.news https://crypto.news/address-poisoning-attacks-drains-100k-dollars-usdt/