CoinDesk published an op-ed by Zach Herbert, CEO of Foundation, stating that attackers exploited a vulnerability in Coldcard's firmware that led to insufficient randomness in wallet seed generation, stealing nearly $114 million in Bitcoin from over 709 addresses. The vulnerability entered the codebase in March 2021 and was publicly present for over five years. The article argues that the Bitcoin community outsourced judgment on verification to individuals, leading to insufficient security reviews, criticized attacks on independent researchers, and emphasized the strict enforcement of the "don't trust, verify" principle.