The intentional lack of specifics has me concerned that any C language project has vulnerabilities baked in, and disclosure of the particular vulnerability would lead to further waves of hardware wallet hacks. This post scares me out more than the the actual cold card incident.