P.S.I think the current case is the lesson for some people who blindly rely on wallets, seeing the open-source 'magnet' from their developers. An entropy-related flaw existed in Coinkite's firmware for a long time, but it turned out that no one was actually reading their code.
That's because ColdCard's code isn't open source.
Years ago, ColdCard switched their code from being open source to being "Source Verifiable" in order to prevent other developers from legally using ColdCard's code on their own projects. That decision, based on greed and hubris, had brutal consequences.
It led to fewer devs using ColdCard's code.
Fewer devs using the code meant fewer devs finding errors and issues.
Fewer devs finding errors and issues meant errors and issues weren't fixed... such as the error in how ColdCard was generating seeds with nowhere near enough randomness.
The error was found by hackers who exploited it to find wallets with a balance, which they drained this week.
This is a perfect example of why open source matters.