Well worth a listen everyone.

npub1cgmkpplph6pd7ajut4cwktl2mczxtzlqvxv3vv2ez7r9sjc926csnvtnyr
hex
8463bf05d5c34b857a843725d3d16c74621f5531cebbe656e21bdae1379191acnevent
nevent1qqsggcalqh2uxju902zrwfwn69k8gcsl25cuawlx2m3phkhpx7gertqprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsvydmqslsmaqklwew96u8t9l4dupr930sxrxgkx9v30pjcfvz4dvg8veew8Kind-1 (TextNote)
↳ 回复 事件不存在
4ab5896176f8d5bbba7fbd9095e11ffaee23a2e900d80bd9874f9db919dbadd4...
Well worth a listen everyone.
Transcript from nostr:npub1dg6es53r3hys9tk3n7aldgz4lx4ly8qu4zg468zwyl6smuhjjrvsnhsguz ‘s substack
PART 1: THE TREZOR INCIDENT
Yesterday Trezor confirmed a data breach at one of its shipping partners, exposing customer order details, and in this video I’ll walk through what happened, what it means, and the self-custody best practices worth tightening.
But first we need to talk about what’s happening to self-custody, because I feel there’s a multi-front attack on bitcoin and specifically on self custody, and the last couple of weeks make that hard to ignore.
That matters because self-custody isn’t a fringe practice, more than 45% of bitcoin is held in self-custody today, according to River. And I think that’s exactly why there’s a real push to reduce that number and get users custodying their bitcoin with third-party custodians instead, because the more that shifts, the more it chips away at bitcoin’s strength as a permissionless asset. And yet, look at what’s piled up in just the last couple of weeks.
It started with Coldcard, a firmware flaw that quietly weakened seed randomness, draining over 1,800 Bitcoin from thousands of addresses. Then BTCPayServer, exploited to empty Lightning nodes. Then Boltz, hit by relentless AI-assisted attacks until its founding team stepped down and handed the company off, and days later Lightning wallet ZEUS pulled its own infrastructure offline after a separate cyberattack. And now, this week, Trezor disclosing a shipping partner breach that exposed customer data.
Urgent: Coldcard (Bitcoin Hardware Wallet) Users Need to Move Their Coins, Here’s What Happened Urgent: Coldcard (Bitcoin Hardware Wallet) Users Need to Move Their Coins, Here’s What Happened EFRAT FENIGSON · 31 JUL Read full story All of this landed right around Bitcoin’s contentious BIP-110 activation window. I’m not saying that’s cause and effect, but five incidents in the same stretch of weeks is not something to wave off as coincidence. It reads like a multi-front attack on the credibility of self-custody itself, and headlines are pushing the same message: self-custody is dead, you can’t trust yourself to custody your own money, you need someone else to hold it for you.
But I reject that framing. It may not be for everyone, and some people genuinely need help, but it’s still a valid approach. There are many ways to hold, secure, and transact with Bitcoin, and each person, business, or institution should use whatever fits them best.
I also think we’d be lying to ourselves if we didn’t admit these incidents are teaching us something real. We’ve gotten comfortable, and that’s exactly where security fails. So instead of getting defensive, let’s actually learn from this and tighten what needs tightening.
Here’s what Trezor disclosed.
Trezor put out an official statement on August 13th about a breach at ShipMonk, one of the shipping providers they use to fulfill orders. An unauthorized party gained access to systems holding customer data. The exposed KYC information includes names, phone numbers, emails, and shipping addresses, of roughly 14,000 people who ordered from the US, UK, Sweden, Colombia, Brazil, Italy, or Portugal between May 10th and August 8th 2026. If you placed an order during that time, check your email to see if you received a message from [email protected] about it.
The reason the number isn’t higher is Trezor’s own data retention policy. They retain order data for only 90 days after delivery, and require the same from their shipping partners, so anything older simply wasn’t there.
Trezor also says this is the first time in their thirteen-year history that a breach has exposed customer phone numbers and shipping addresses.
Important to mention, as I’ve seen some people and companies spreading misinformation about it: devices and wallets were NOT affected by this. This is an order data breach, which poses an operational security risk, not a funds risk. Nobody’s Bitcoin was touched, no private key was exposed, and Trezor’s own systems were not compromised. This was strictly a data breach.
PART 2: SELF-CUSTODY BEST PRACTICES
So let’s get into the actual takeaways here, a few self-custody best practices worth tightening up right now.
If you were affected, know this: it doesn’t put your funds at risk directly, but it does put you at risk of phishing, and since shipping addresses were exposed, it also raises the risk of a $5 wrench attack, meaning physical targeting based on someone knowing where you live and that you own a hardware wallet. Whoever accessed this data now has exactly what they need to send convincing phishing emails, fake calls, fraudulent letters impersonating Trezor, your bank, or an exchange.
Never enter your seed phrase anywhere but your device. Not a website, not an app, not a support chat. This is the single most repeated piece of advice from every hardware wallet company after every incident, because it’s still the number one way people actually lose funds. Verify any Trezor communication through official channels only. No legitimate company will ever ask you for your recovery words, your seed phrase, not by email, not by phone, not on a website. Btw the same goes for communication from me or anyone else, there are so many impersonators who are trying to scam people pretending to be someone they’re not. I would never DM you to ask for your personal information. Consider a multisig setup for meaningful amounts. Spreading trust across multiple devices or locations means a compromised seed can’t take everything. When it comes to multisig, remember it doesn’t necessarily require a custodian, it doesn’t require KYC, giving up your privacy, or a company signing on your behalf. One of Bitcoin’s first principles is removing trusted third parties, not scaring you into adding them back in under a different name. Limit what companies know about you when you order. Use an email address that isn’t tied to your real identity when you place the order. Pay with bitcoin if you can, and if you can’t, use a disposable debit card instead of your regular one. Ship to a PO Box or delivery center, instead of your home address to limit how much of your physical location is on file, though keep in mind ID is usually still required to collect from one. Trezor is also rolling out an anonymous delivery option, using locker pickup, neutral packaging, and generic sender details, with automatic deletion of shipping data after delivery, aiming for the EU by September and the US by the end of the year.
WHY THIS MATTERS
Lastly, I want to apologize for not stressing these best practices earlier, I’m aware it could have protected people from this data breach, and as someone who recommends Trezor products, I apologize if you got affected. I also want to emphasize something about every company or product I talk about on my show. Nothing is risk free. I bring you the people and the products I find compelling, but that is never a substitute for your own research. Always look into the security practices of anything you use to store or move your money, and always decide for yourself what level of risk you’re comfortable carrying.
Stay sharp, vigilant, and safe out there.
15.08.26
#efratfenigson
原始 JSON
{
"kind": 1,
"id": "8463bf05d5c34b857a843725d3d16c74621f5531cebbe656e21bdae1379191ac",
"pubkey": "c2376087e1be82df765c5d70eb2feade04658be061991631591786584b0556b1",
"created_at": 1786800431,
"tags": [
[
"e",
"4ab5896176f8d5bbba7fbd9095e11ffaee23a2e900d80bd9874f9db919dbadd4",
"wss://relay.snort.social",
"root",
"6a359852238dc902aed19fbbf6a055f9abf21c1ca8915d1c4e27f50df2f290d9"
],
[
"p",
"6a359852238dc902aed19fbbf6a055f9abf21c1ca8915d1c4e27f50df2f290d9"
],
[
"p",
"6a359852238dc902aed19fbbf6a055f9abf21c1ca8915d1c4e27f50df2f290d9"
],
[
"t",
"efratfenigson"
],
[
"client",
"Damus"
]
],
"content": "Well worth a listen everyone.\n\nTranscript from nostr:npub1dg6es53r3hys9tk3n7aldgz4lx4ly8qu4zg468zwyl6smuhjjrvsnhsguz ‘s substack\n\nPART 1: THE TREZOR INCIDENT\n\nYesterday Trezor confirmed a data breach at one of its shipping partners, exposing customer order details, and in this video I’ll walk through what happened, what it means, and the self-custody best practices worth tightening.\n\nBut first we need to talk about what’s happening to self-custody, because I feel there’s a multi-front attack on bitcoin and specifically on self custody, and the last couple of weeks make that hard to ignore.\n\nThat matters because self-custody isn’t a fringe practice, more than 45% of bitcoin is held in self-custody today, according to River. And I think that’s exactly why there’s a real push to reduce that number and get users custodying their bitcoin with third-party custodians instead, because the more that shifts, the more it chips away at bitcoin’s strength as a permissionless asset. And yet, look at what’s piled up in just the last couple of weeks.\n\nIt started with Coldcard, a firmware flaw that quietly weakened seed randomness, draining over 1,800 Bitcoin from thousands of addresses. Then BTCPayServer, exploited to empty Lightning nodes. Then Boltz, hit by relentless AI-assisted attacks until its founding team stepped down and handed the company off, and days later Lightning wallet ZEUS pulled its own infrastructure offline after a separate cyberattack. And now, this week, Trezor disclosing a shipping partner breach that exposed customer data.\n\nUrgent: Coldcard (Bitcoin Hardware Wallet) Users Need to Move Their Coins, Here’s What Happened\nUrgent: Coldcard (Bitcoin Hardware Wallet) Users Need to Move Their Coins, Here’s What Happened\nEFRAT FENIGSON\n·\n31 JUL\nRead full story\nAll of this landed right around Bitcoin’s contentious BIP-110 activation window. I’m not saying that’s cause and effect, but five incidents in the same stretch of weeks is not something to wave off as coincidence. It reads like a multi-front attack on the credibility of self-custody itself, and headlines are pushing the same message: self-custody is dead, you can’t trust yourself to custody your own money, you need someone else to hold it for you.\n\nBut I reject that framing. It may not be for everyone, and some people genuinely need help, but it’s still a valid approach. There are many ways to hold, secure, and transact with Bitcoin, and each person, business, or institution should use whatever fits them best.\n\nI also think we’d be lying to ourselves if we didn’t admit these incidents are teaching us something real. We’ve gotten comfortable, and that’s exactly where security fails. So instead of getting defensive, let’s actually learn from this and tighten what needs tightening.\n\nHere’s what Trezor disclosed.\n\nTrezor put out an official statement on August 13th about a breach at ShipMonk, one of the shipping providers they use to fulfill orders. An unauthorized party gained access to systems holding customer data. The exposed KYC information includes names, phone numbers, emails, and shipping addresses, of roughly 14,000 people who ordered from the US, UK, Sweden, Colombia, Brazil, Italy, or Portugal between May 10th and August 8th 2026. If you placed an order during that time, check your email to see if you received a message from [email protected] about it.\n\nThe reason the number isn’t higher is Trezor’s own data retention policy. They retain order data for only 90 days after delivery, and require the same from their shipping partners, so anything older simply wasn’t there.\n\nTrezor also says this is the first time in their thirteen-year history that a breach has exposed customer phone numbers and shipping addresses.\n\nImportant to mention, as I’ve seen some people and companies spreading misinformation about it: devices and wallets were NOT affected by this. This is an order data breach, which poses an operational security risk, not a funds risk. Nobody’s Bitcoin was touched, no private key was exposed, and Trezor’s own systems were not compromised. This was strictly a data breach.\n\nPART 2: SELF-CUSTODY BEST PRACTICES\n\nSo let’s get into the actual takeaways here, a few self-custody best practices worth tightening up right now.\n\nIf you were affected, know this: it doesn’t put your funds at risk directly, but it does put you at risk of phishing, and since shipping addresses were exposed, it also raises the risk of a $5 wrench attack, meaning physical targeting based on someone knowing where you live and that you own a hardware wallet. Whoever accessed this data now has exactly what they need to send convincing phishing emails, fake calls, fraudulent letters impersonating Trezor, your bank, or an exchange.\n\nNever enter your seed phrase anywhere but your device. Not a website, not an app, not a support chat. This is the single most repeated piece of advice from every hardware wallet company after every incident, because it’s still the number one way people actually lose funds.\nVerify any Trezor communication through official channels only. No legitimate company will ever ask you for your recovery words, your seed phrase, not by email, not by phone, not on a website. Btw the same goes for communication from me or anyone else, there are so many impersonators who are trying to scam people pretending to be someone they’re not. I would never DM you to ask for your personal information.\nConsider a multisig setup for meaningful amounts. Spreading trust across multiple devices or locations means a compromised seed can’t take everything. When it comes to multisig, remember it doesn’t necessarily require a custodian, it doesn’t require KYC, giving up your privacy, or a company signing on your behalf. One of Bitcoin’s first principles is removing trusted third parties, not scaring you into adding them back in under a different name.\nLimit what companies know about you when you order. Use an email address that isn’t tied to your real identity when you place the order. Pay with bitcoin if you can, and if you can’t, use a disposable debit card instead of your regular one. Ship to a PO Box or delivery center, instead of your home address to limit how much of your physical location is on file, though keep in mind ID is usually still required to collect from one.\nTrezor is also rolling out an anonymous delivery option, using locker pickup, neutral packaging, and generic sender details, with automatic deletion of shipping data after delivery, aiming for the EU by September and the US by the end of the year.\n\nWHY THIS MATTERS\n\nLastly, I want to apologize for not stressing these best practices earlier, I’m aware it could have protected people from this data breach, and as someone who recommends Trezor products, I apologize if you got affected. I also want to emphasize something about every company or product I talk about on my show. Nothing is risk free. I bring you the people and the products I find compelling, but that is never a substitute for your own research. Always look into the security practices of anything you use to store or move your money, and always decide for yourself what level of risk you’re comfortable carrying.\n\nStay sharp, vigilant, and safe out there.\n\n15.08.26\n\n#efratfenigson",
"sig": "27da912cc8ad8ad0a8e19676c72e8411afd1efda7198c7bd47fa014ec49fe76e538a2f6777cdb5112a632c83c33efc8f0e148ee79be2fa1f88ffd7d9e8304131"
}