> Because, in the applied world, upstream bugs in "secure" system RNGs have been the cause of stolen crypto [...]
You mean javascript libraries that do a bit of Math.random() and a miniscule amount of mixing, that had been widely considered poor practice for years while old bitcoin wallet generator websites were burning users with it?
Has any actual serious CSPRNG exposed bitcoin wallets?
Yes, numerous times. Here are some famous ones:
https://android-developers.googleblog.com/2013/08/some-secur... https://illbloom.org/articles/cryptojs-vulnerability/ https://www.ledger.com/blog/funds-of-every-wallet-created-wi... https://milksad.info/disclosure.html https://secbit.io/blog/en/2024/01/19/trust-wallets-fomo3d-su...