"The people affected by this did everything right. They generated their seed on an air-gapped device using a random number generator..."
No
@Simply Bitcoin, they did not do everything right.
They made the two mistakes every Bitcoiner should avoid:
- Trusting the device to generate the seed on their behalf.
- Failing to verify whether the generated seed was actually secure (I'm sure most of you guys have heard of Ian Coleman's tools).
In other words, they replaced Bitcoin's core principle of "Don't trust, verify" with "Do trust, don't verify."
I'm sorry, but that is not "doing everything right."
If they had generated their seed themselves using dice and protected it with a strong passphrase, they would have had time to move their funds.