In March 2021, Coinkite introduced an entropy bug into the firmware for their Mk3, Mk4, (and the yet to be produced Mk5 and Q) line. Instead of utilizing proper hardware-based entropy, the devices used software-based entropy partly predictable from the unique ID/serials, time/clock registers, and related states of their chips.
The result: instead of utilizing 128 or 256 bit entropy, they were down to just 40 bits (for Mk3) or 72 bits (for the others), under optimistic assumptions. To grasp the difference in scale, see the video below. Essentially, the bug reduced the problem for the attackers from finding one atom in over a billion galaxies to finding one atom in a single organism.
Those who were relying purely on the device generated seed were vulnerable to having their seeds brute-forced by attackers. Those who had an additional passphrase on top of the seeds generated by the device now relied much more on the entropy of the passphrase itself. Those who generated their own enropy (through the use of coins/dice) to generate the seeds were fine.
In July 30-31, 2026, funds were swept en-masse from addresses generated using Mk3. With 40 bit entropy, even hobbyists with the right hardware were able to cover the whole search space. The drain continued in different waves for the next weeks. Some Mk4 and later addresses were also swiped, although, if the corresponding entropy is indeed approximately 72 bits, the resources required for the brute force would be significantly higher than those afforadable by hobbyists. (Rough estimates: 10000 GPUs assuming 1 billion checks per second per GPU would take over a decade to generate half the seeds of this space, and the electricity costs would be around $30 million.) But it is worth emphasizing that the actual entropy might turn out to be much lower than 72 bits, in which case the brute force might become more practical.
As of August 14, at least 1700 Bitcoin had been drained as a result of this compromise. That is over $130 million at current exchange rates.