1,196 wallets were drained in 41 minutes.

A weakened random-number source let the attacker recompute private keys directly, without touching any device or user.

Owners cannot tell if their own seed came from the flawed firmware, and losses may grow.

Sources: CoinDesk