The attack on COLDCARD HW wallet is probably one of the worst ones in crypto history.
COLDCARD was seen as one of the most secure and paranoid option for self-custody, with proper airgapping and many security measures. Its users did basically everything right, yet got hacked.
A bug in the RNG for how seed phrases are generated, undiscovered for 5 years, meant hackers can re-generate seed phrases on their own.
Owning a Mk3 and being on the exposed firmware myself, I was up late last night scrambling to access it and see if I was affected. Luckily, and more by happenstance, my seed predates the RNG bug. First close call on a hack in a long time. But this isn't true for a lot of people, and these people are fucked now despite doing 95%+ of self-custody right.
Not hopeless, there are several ways to mitigate these things, but definitely not good. Unlike e.g. previous CEX hacks, this one strikes at the very core of self-sovereignty, self-custody, and what a big part of this technology is about.