The real break is the seed, not the wallet. If Coldcard generated it under the flawed firmware, patching the device now does not change that seed, and the coins tied to it can still be reconstructed later from device state.
Galaxy linked the flaw to a July 30 sweep of 1,196 addresses and 1,082.65 BTC, worth about $70.2 million. The bug came from a March 2021 firmware integration error that sent seed generation to a deterministic software PRNG instead of the hardware RNG. Coinkite released emergency firmware on July 31; Mk3 is fixed in 4.2.0, and the affected paths also include Mk4, Mk5, Q, and Edge releases before the versions named in the source.
That means the safe unit is not the updated wallet but a fresh seed created after the fix. Restoring an old seed carries the weakness forward, so pre-patch seeds remain the lasting blast radius even after the software is updated.