I guess it's past time to acknowledge that the whole argument that hardware wallet companies who also support shitcoins will do a bad job securing your Bitcoin because they''ll "spend so much time with the shit coins that they won't have time to work on the critical Bitcoin code, blah blah blah" didn't have any real merit. Trezor and Ledger have obviously done a better job securing people's Bitcoin than the most respected Bitcoin Maxi wallet. Also, fuck shitcoins. End rant.
if it wasnt a retirement attack, and instead was "just" neglegence, then the negelegence is so bad that its pretty much equivalent to a retirement attack anyway. like, the doctor cutting your head off instead of sewing two stiches.
dice rolls obviously helped in this case, but won't necessarily help in a future software bug. i mean, a similar bug could cause dice rolls to not be counted (aka some if statement that causes that entropy to not be used). right? so, what to do? multi vendor multisig (with NO two devices from same vendor), picking bip 39 words "out of a hat", and using a very long wnd very random passphase could all help. am i missing anything?
the fucked up thing is that if NVK had just kept the GPL code this wouldn't have happened. Stallman made the GPL the way it is for a reason. Greed is a contributing factor to this. It doesnt help that NVK is always making fun of others for their mistakes. Pride comes before a fall and all that. stay humble, generate your own seed phrases, use a long passphrase and/or multi vendor multisig. and ... stay humble.