Nope. def did.
Nope. def did.
I kinda wonder if they were taking older hard wallets and seeing if they could find any vulnerabilities and that they figured out that the MK2/MK3 wallets had this problem and just exploited it. No doubt any hacker groups are following the same methods. The other option is someone inside knew about the flaw and shared it or a group was using a type of corporate espionage and discovered it from internal sources.
Damn, good post… I agree with the recommendations after all of this. Those impacted by this is heart breaking and I feel all the empathy pain…
Doesn't even sound like an actual "hack." It was just lousy firmware. The door was already opened when the developers shipped that firmware. It was just a matter of time before someone opened the door.