I guess the bright side is that the damage was minimal, and the bug allowed an opportunity for coordinators to establish a history of trustworthiness (despite there being no inherent trust requirement in coordinators at the protocol level).
Do you think it a solution to copy/emulate the post-snacks solution as done for Wasabi, for Coldcard firmware if there's going to be a post-coinkite moment? (not sure if this is possible wrt the signing of the firmware, fwiw.)
The worst drain exploit (1% coordinator fee) that Wasabi had was discovered internally and fixed (but not deployed quickly enough): https://github.com/WalletWasabi/WalletWasabi/pull/13191
I guess the bright side is that the damage was minimal, and the bug allowed an opportunity for coordinators to establish a history of trustworthiness (despite there being no inherent trust requirement in coordinators at the protocol level).