Basically when you buy a collectable, you are trusting the maker to use sufficient randomness for the key generation. It's not that different from hardware wallets in that respect tbh.
A few years ago, there was an incident where all ColdKey (not to be confused with Coldcard) coins were remotely swiped by the creator one day and a lot of people got rugpulled.
My Cold Keys Just Got Swiped! All Cold Kuntz!! Coldkey was pre planned and malicious in nature.
ColdCard was dumb as shit for them not checking their own software randomness or in intentionally bypassing it.
What Went WrongFirmware Bug: A code error in Coldcard firmware (introduced around March 2021) bypassed the device's hardware True Random Number Generator (TRNG).
Weak Randomness: Devices fell back to a predictable software pseudo-random number generator (Yasmarang), drastically reducing the entropy (randomness) of generated 12 or 24-word seed phrases.
Exploitation: Attackers used the predictable output space to brute-force private keys and steal millions in Bitcoin from single-signature wallets

Read here>>
https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep We have a saying in crytpto....
VERIFY DON'T TRUST And damn did we fail. I wish I had the ability to have the knowledge to test any wallet cause I would have.