If the wallet was never password-protected, the hacker can drain the funds instantly.

Linux users will find the directory in their home folder. It is also hidden by default and begins with a dot ( . ):

In 2021, a well-known crypto trader backed up his wallet.dat to a misconfigured Synology NAS (Network Attached Storage). He set the folder to “public” for convenience. A hacker using the query intitle:index.of wallet.dat password found the NAS within 48 hours.