"...to those affected it seems like a failure of decentralization, the actual truth of the matter is the opposite. There are many hardware wallet providers and only one small company was affected by this. Ironically, if that company had just used the code that all the other companies use... there would have been no problem."
While not using nominal entropy was a mistake, using different code than 'the rest' of wallet makers is a feature of decentralization that is the reason decentralization out competes centralization. Had there been a 'sploit that affected 'the rest' of the wallets, being different than them would have demonstrated decentralized products prevent all users from being harmed by a single 'sploit. The reverse being true - while harming the users of the one product - demonstrates the strength of decentralization as only the users of the affected product were harmed by the error of the makers. It also demonstrates the weakness of trusting RNGesus compared to rolling your own, and the wallets released going forward should be improved as a result of this event. Your understanding of the risks of RNGesus also demonstrates the value of decentralization, as you individually set the entropy rather than just running with the centralized herd, and that appears to have secured your assets from this 'sploit.
I also consider QR codes weaknesses because they aren't often read by people, but are a black box with unknown risks to most folks. Most, like me, haven't learned to read them and folks just use them anyway.
Thanks!
RE: Everyone Panic! ColdCard Bitcoin-only wallet HACKED!