The crazy thing about the Coldcard bug is that it's almost identical to the libbitcoin issue with bx from 2023 known as "Milk Sad". How many more will rely on an RNG to generate keys?
People using Bitbox, Jade, Trezor etc should all be taking a hint if they relied on an RNG too. You don't get time to fix it when a bug is found. Assume your seed is compromiseable unless you can prove otherwise.
Milk Sad: /home
