In the middle of the night on July 30, $70.2 million worth of Bitcoin were stolen from addresses created by hardware wallet manufacturer Coinkite's Coincard products. A firmware bug weakened the recovery phrases generated by several generations of their devices, allowing an attacker to reconstruct their users' private keys without physical access to the devices.
They don’t need to. They just calculate all private keys derived from the ~40 bits search space of all Mk3 Coldcards and sweep any that have funds. ~40 bits is only ~1 trillion combinations, so it’s trivial to just check all possibilities relatively quickly once you know how to calculate them.
They don’t find it. The random number generator for the private key was rubbish and had only 40 bits of entropy so attackers brute forced private keys until they got hits with BTC in them. I highly recommend antimoonboy’s coverage on it. Here it is timestamped.