A close friend’s @Ledger wallet was drained a week ago. No malicious approvals, no known seed exposure, and the recovery phrase has stayed locked in a safe. He had not accessed the Ledger in nearly 2 years. We still have no clear explanation.
I believe Coldcard is most likely engaging in an inside job. The fact that they previously encouraged users to generate seed phrases with their own devices and then import them into hardware wallets from other brands already looked highly suspicious.
In the blockchain world, the generation of mnemonic phrases should never be entrusted to any brand or company.
I recommend using the open-source tool https://t.co/IZeaNJCNqT and creating the seed with true randomness obtained by rolling physical dice. Only entropy from the physical world is genuinely trustworthy.
On top of that, always add a passphrase as a second layer of encryption. Even if the seed phrase is leaked, there will still be another layer of protection.