Reports of funds drained on coldcards happening years before the big heist are emerging by the dozen. The ceo of this company has a long history of shaming and ignoring people reporting issues with their products. Their bug bounty reward is basically a mug (look it up). And they have the audacity to tell you that the "hacker" could have done the right thing and responsibly disclosed. LOL.