Did someone notice a suspicious part of the firmware, realise that the randomness was weaker than it should have been, calculate all the possible seeds and then scan the blockchain to see whether any of those wallets contained funds?
Hackers are constantly trouble shooting security systems looking for vulnerability. The suspicion in thus case is that it was discovered years ago when those wallets were opened, the hacker got access to the seed phrase and sat on them for a while to allow the owners move funds into them before sweeping.
Do hackers systematically examine the firmware and source code of different hardware-wallet brands such as Coldcard, Trezor and Ledger, looking for weaknesses in the way they generate seed phrases? Do they spend months testing different devices until they find one that produces seeds from a limited or predictable set of possibilities?
Yes and yes.
I understand that developers are human and that mistakes can happen. How does something this important make it into production without being detected?
It's as you said, humans make errors. It also missed the eye of everyone as the codes are open source but no one spotted the vulnerability.
- Jay -