It's a bug coinkite should have found long ago. It's a bug that the open-source community could have found long ago.
I suspect the failure on both counts is largely due to a lack of eyes on a specific function (reliance on RNG for seed generation) which is mostly avoided by those who are even capable of detecting such a bug.
*it's probably best for ALL signing devices to just discontinue offering this inherently risky convenience.