Obviously still able to be bruteforced, but at the very least acts as a buffer to buy you time in exactly this type of situation. And an opportunistic attacker wouldn't have reason to keep trying to brute force it once they're in the main wallet to begin with.
Even in the case of an attacker who knows you have one, if you have high enough entropy, e.g. multiple words, that can be the difference between being vulnerable or not.
quotingIf Coldcard taught us anything it's that you shouldn't blindly trust something is secure just because the code is on GitHub.
nevent1q…gn3x
Feel bad for any plebs who had their wallets breached though. And I hope the Trezor guys compile their firmware correctly...

