Coldcard shows the challenge of a bitcoin-only business

The Coldcard hack shows how hard it can be to run a bitcoin-only business. While building the hardware wallet itself might not be that expensive, it is a one-off cost. The associated ongoing software updates, paying for the updates to be professionally audited and running a credible bug bounty program to catch problems before they effect users are real ongoing, recurring costs that continue on for as long as anyone is using your wallets. Businesses that don't charge a subscription fee need to pay for these recurring costs by one-time sales of wallets.

Bitcoin-only wallet companies have both a much smaller total addressable market and one that tends to use their wallets much less frequently than the broader "crypto" ecosystem. In contrast, competitors like Ledger which target the entire crypto market, not only sell many more wallets but can also have token projects pay for the auditing of at least some of the code.

I'm not actually sure if that's what happened in this case, but there's a lesson to be learned. Suspect vendors that voluntarily restrict their addressable market, especially when they pitch a smaller market as somehow better for your security.