ColdCard was NOT open source. ColdCard was Source Verifiable.
What's the difference? Open source means anybody can use the code, even in their own work.
Source verifiable means anyone can read the code, but they can't use it in their own work. So, what's the incentive for experts to read it? And even for those who do read it... some bugs aren't likely to be spotted on sight. It isn't until you tinker with it that you realize something behaves unexpectedly.
ColdCard got greedy. They didn't want people using their code. Their hubris and greed led to them getting wrecked, and that would be great if ColdCard users didn't get wrecked too.
Which brings us to Coinkite’s “open” code. The last part is key. If you’d used MIT or GPL, others could fork it or provide fixes for a fee or sell competing products. With the current license anyone can read it, but they can’t make competing commercial products. That means the only people with an incentive to deeply analyze the code are researchers looking to make a reputation, who are unlikely to closely review entropy generation, or people looking to exploit it, who are likely to closely review entropy generation.
Deeply analyzing entropy generation happens if you get paid to do so, or if you’re trying to exploit it. That’s why this bug sat around for 5 years. Coinkite gets the PR of open source, with the legal protections of closed. They got the marketing benefit of both models and the security benefit of neither. Illusory security through questionable licensing.