Autistic pushback on the last point.
Even if nvk found the bug before any hacker, what could they have done about it? The hackers could exploit it faster than most users would be at moving their coins. It might have prevented a decent amount but most cold storage coins would still be swiped.
I know for a fact that every other hardware and software wallet manufacturer is auditing their own code right now, but what if they do find a similar vulnerability? If they find they have a similar problem, the moment they tell their customers to move their funds, hackers will beat most users to the punch.
CC was fine until the bug got discovered, but even if they had found it themselves before the hacker, they can't get the word out without letting the hackers know. This was set in stone the moment they ever shipped a device with the bug. Even if they noticed it a year later, that would only help devices after that point.
View quoted note →