My understand is that the details that resulted in this failure where sitting out in the open for years.
However to taking this to jump to “open source doesn’t work / has failed” is a strange and hasty logical mistake to make.
What we are seeing with the ColdCard exploit like IS minimal damage. That it tools someone using AI to find this vulnerability likely means it was found as fast as it would have been.
Further in closed source context, the company has an overwhelming incentive to lie and deflect and hide the issue on failures like this because it’s better for the reputation, and therefore revenue that way.
Also, there are elements of this failure that are at “patchable,” particularly for keys that have already been generated.
Regardless, bitcoin is choose your own adventure. If you feel more comfortable using a Ledger wallet that has to split security budget across 10000 coins (all of which have no value except bitcoin) and ship with closed source embedded remote key extraction software (don’t worry, it’s opt in only!), then I’m happy that this solution is there for you.

