Always pick a slow news day to announce the new phase of a project.
Introducing #safebox #acorn - once released, it will be a separately installable component to manage identity, funds and records that live independently on replaceable relays, mints and blossom servers.
Unfortunately, the big lesson here is - don't upgrade hardware wallet firmware unless the company has gone through a third-party audit that is signed off.
My bet this attack was weeks in the making. Once the attackers assembled enough private keys for high value utxos they executed.
My biggest disappointment is relying on a hardware vendor that has 'Don't Trust. Verify.' plastered all over their product marketing and the primary motivation that led to the bug was a 'get out of open source' licensing issue.
Let this be a lesson for all in the industry.
'Not your keys, not your coins' rings a bit hollow now.
It's more like: 'God plays dice for those who self-custody.'