You forgot about their lack of public source code repository. Talk about significant problems for an "open source" project! Go try and download the old 6.2 or 6.1 versions. If you feel bold, go ask for a copy in their forum, or better yet, offer old TrueCrypt source code for download. They scare the hell out of me. They do now advertise a US address next to some Air Force base in Nevada. No I'm not paranoid, I speak only truth.
Edit: This is all common knowledge and has been for a few years. Wikipedia has all the details. The Czech Republic connection with the Trademark, the anonymous/unnamed developers, etc. The new (as of this year) mailing address in the US, the fake domain name registration, etc.
One last edit: TrueCrypt is probably fine protection against common thieves, but enough bits may have been knocked off of it to make it "acceptable" for export. If I was a Russian Spy, I would not touch it with a ten foot pole.