Fixing the Coldcard issue is "easy" -- just audit the code thoroughly.
But can manufacturers mitigate supply chain attacks risks?
Users can by using fake addresses or POBoxes detached from their identities, but not every normie will do that.
Wonder what your thoughts on this are, @Foundation