The secure elements in the products have had attacks done on them several times. The maker of the SE chips only released incremental updates that do not fix the fundamental flaw.
The original company that made the SE IC is long defunct too. It’s like maintaining an old codebase with no one around.
There are also several critical flaws in the design of the Coldcard that allow undetectable supply chain attacks.