From my own analysis, it is an accident, but an extremely preventable one.
The best way to explain it would be that you are constructing a building, and decide to cheap out and don’t get any proper architectural engineers or inspectors. At least you copy someone else’s blueprint that is proven to work.
Then you want it to look different in a hurry, so you ask a random friend to quickly modify the design. They tested it and looks fine, but then you modify it yourself, introducing a flaw that will lead it to collapse. And then you market it as if it was approved by an engineer.
At all points, Coinkite Inc. could have invested in people specialized in information security. They could have acted with caution when adding a new dependency that handles the generation of seeds, reviewing it. They could have checked that its changes to the configuration will not cause any adverse effects. They could have slowed down and waited. They could have known their limits.
At no point did they have the obligation to skip any of these things. They also never had the obligation to present it with security claims that they couldn’t back up.
I feel bad for the people affected, but I also feel that they fucked around and found out. In some aspects, this could be considered fraud, as Coinkite pretended to have expertise in fields they did not know much about.
(I have been saying this for years now. Their security incompetence has been clear for a long while.)

