Probably this was already happening since there are severeal online claims of users that have their btc lost using this hardware.
... nobody would have noticed and blamed coldcard.
it could be not excluded that they have just collected the majority of the keys before claiming the whole attack.
it worth mention that there are more "patterns" of attackers, probably there isn't only one cluster/user.
[I read some retard comment about "white hacker" trying to using the same exploit for "save bitcoin from the black hacker"

]
The amount stolen doesn't look so basic or easy to hide.
Probably we are just not ready to understand and assimilate this issue...
The first has been to underestimate the risk on rely on third parties.
The second has been completely voided the concept of trust - I trust another entity making hardwares and not just my self using a tutorial
Third, if bitcoin would become what we are expecting, it's clear that any amount could become impressively precious.
Forth (worst point) this has been used as wrench for attacking self custody and continue to blame on people that want have their sovereignity managing bitcoin in totally autonomy.