If Coldcard taught us anything it's that you shouldn't blindly trust something is secure just because the code is on GitHub. Feel bad for any plebs who had their wallets breached though. And I hope the Trezor guys compile their firmware correctly...