Unfortunately we trusted another software and hence the keys were compromised but it's not just ours but a widespread RNG attack
It would be interesting if you mention that software for comparison.
Because it could be the entropy or the mini private key itself. For example: the script in the OP produces a 256-bit entropy but about 34% of it is discarded when generating the mini private key. So its overall security is reduced to about 2^168 which is still secure in today's standard. (e.g.: old unspent Casascius Coins)