India dumps entire truckloads of plastic trash straight into the rivers.
Meanwhile we’re forced to use paper straws that dissolve, bottle caps that never come off, ULEZ charges and carbon taxes.
Net zero is a scam run by people who hate you.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026.
The data exposed:
- Full names
- Shipping addresses
- Phone numbers
- Email addresses
The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).
All affected customers have been contacted separately by email.
Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts.
NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels.
We are deeply sorry to the community and those affected.
We are investigating this situation and will post updates on our blog:
https://t.co/JGrttMs4Ev
"Bitcoin wallet industry is so petty and dramatic."
This is a real quote from today and I've seen similar sentiment over the last week. It's wrong.
The Bitcoin wallet industry is not filled with infighting. Only one CEO of one company is responsible for all of the vitriol: NVK.
My company, @FoundationHQ, is friendly, collaborative – and yes, competitive – with others in the wallet space. We interact with or have previously interacted with @Blockstream, @BitBoxSwiss, @Trezor, @Bitkey, @SeedSigner and others over the years. I have respect for them all.
I fiercely criticized Bitkey, for example, and have amended my critiques as they have addressed them. Bitkey now has privacy guarantees and a screen – a big win for the ecosystem.
I'll even occasionally interact here on X with @P3b7_ of @Ledger. While I don't agree with Ledger's approach most of the time, Charles respectfully engages in good faith. Ledger maintains one of the best security research teams in the industry and participates in responsible disclosures that have helped secure many companies.
There is no industry infighting. There is no toxic culture amongst wallet vendors. There is just NVK.
NVK had a unique style and strategy that was difficult to defend against. It wen't something like this:
(1) NVK aggressively attacks competitor or security researcher with wild defamatory claims and name calling. "Cloner" "Leach" "Commie" "Maoist" "Terrorist"
(2) Competitor tries to defend himself. "That's not true, we are not cloners, we used some of your open source code but made substantial contributions of our own"
(3) NVK continues to repeat claims across twitter, podcasts, live audiences, etc. Repeats the exact same defamatory statements and name calling dozens of times. More repetition makes it common knowledge.
(4) Competitor points out NVK's poor character or criticizes Coinkite's products or business practices – and is immediately swarmed by others publicly and privately to "keep things civil" "don't cause drama" "stop the infighting" "take the moral high ground"
(5) NVK continues relentlessly but is not called out by the same people for his bad behavior – they only call out anyone who pushes back against NVK. They do not dare call out NVK.
This is a complex strategy that worked for several years. Numerous folks in the wallet industry were targeted, not just Foundation/me.
NVK is relentless and is consumed by targeting others. At one point he had Twitter alerts set up for any mention of "Foundation" or "Passport" and would swarm our mentions with bot accounts. And there's much more.
Most people don't know, for example, that NVK maintains dozens of domain names that point Foundation and Seedsigner to various poor reputation Bitcoin projects like Knots.
I just tried a few domain names in my browser for SeedSigner. https://t.co/JecezJxKPh currently forwards to Bitcoin Knots website. NVK registers and controls these domain names.
Most people also don't know, for example, that NVK sneaks around and gossips to investors and conference organizers – attempting to get funding commits pulled, conference sponsorships canceled, and even sometimes conference attendance canceled – from companies or projects that are on his hit list.
My experience aside, it's no secret that @OpenSats never gave SeedSigner a grant. The reason is obvious.
But now all that is over. For 7 days now the wallet industry has been free of vitriol.
This has been a horrible week for Bitcoin and Bitcoiners. I look forward to collaborating with our fellow industry peers to ensure something like it never happens again.
Thank you.
Looks like Coldcard was a state-backed, inside job spanning multiple years of careful planning.
The revelation of earlier tweets like the one below heavily suggests that this was long premediated by Coldcard insiders.
The heist was optimized around max public shock value and minimum discretion.
Given all the facts, we must answer:
- Why did the attacker completely disregard privacy by consolidating stolen coins into a single address?
- How did the attacker, who clearly planed this for a long time, fail to plan to cover their own tracks?
- Why did the attacker use KYC'd service providers?
- Why did Coldcard make these "wink-wink easter egg" posts about this exact bug around the same time the bug first appeared in the code base?
- If it was merely a "retirement attack," why not exercise discretion so you could actually retire?
- Why did the timing line up with major politically relevant developments like CLARITY and a bear market?
The only theory that answers all these questions well is a state-backed operation involving Coldcard insiders. It was never about the money. It was about attacking self custody, one of the core premises of Bitcoin.
I did not want to make this accusation initially even though I did suspect it. Now the evidence is on my side so I am adding the insider point to the theory.
The folks who think there is no conspiracy need to answer some hard questions:
If you think it is a script kiddie using an open source LLM like Kimi, you need to answer why he would do this but not ask Kimi or Google how to cover up his tracks despite planning at least for a few months.
If you think it was a random Bitcoin hater who doesn't care about the money, you need to answer why Coldcard put out these clearly suggestive tweets at the same time.
(Note: you can say coincidence, that's your right).
Skeptics: I would love to hear your answers!
For me the inside job theory squares all the corners and also explains the company's actions over the last few years.
- Antagonizing security researchers -> less visibility into code
- Discredit competitors -> cause confusion
- Heavily fund the marketing engine -> draw in the hardcore Bitcoiners; promote a strong brand association with self custody
- All these easter eggs + NVK hating plebs -> mock the would-be victims and create learned helplessness
All of this comes together really well to the mess we have today.
Processos contra fundador da Coldcard começam a chegar na justiça brasileira.
Vítimas também estão colocando como réu influenciadores que recomendaram a carteira 👀
Eles têm responsabilidade jurídica?
Aparentemente, tem muita jurisprudência falando sobre a responsabilidade de influencer, porque, de acordo com a justiça, ao fazer publicidade (principalmente paga), o influenciador passa a integrar a cadeia de consumo, como se fosse um “fornecedor” segundo o Código de Defesa do Consumidor (CDC).