Now basically: every single attack that's been described as "theoretical" or "far-fetched" or "only existing in the mind of a paranoid person" did actually happen.
We're talking here about a tiny eSIM implant and a little CPU doing OCR on the fonts appearing on the hardware wallet's screen to read the secrets during set up. So the secure element ain't tampered with.
Not long ago the Coldcard hardware wallet had an issue where it'd fallback to a 32-bit only RNG that could be cracked and so many people got their coins stolen.
Now it's Ledger that sees tampered devices all around the world (in Asia for sure but now there are reports about reseller in the EU selling backdoored/eSIM'ed devices).
For people who own Bitcoin at this point one of the only thing kinda sensible to do is to use multisig schemes, like 2-of-2 or 3-of-3 multisig, where your split the secret over two or three different hardware wallet brands (meaning being able to sign a 2-of-2 wallets requires hardware wallets from two different vendors).
When Ledger hardware wallets came out and people said that seed (the list of words) could be intercepted and relayed by a channel bypassing the computer (here by using an eSIM), people would post explaining that people were nuts if they thought such an attack could be pulled off.
Yet here we are.
And Ledger is responsible for very poor security practices: for example it's impossible to use a Ledger hardware wallet in a fully airgapped/offline way. For you're forced to not only upgrade the firmware but also install the Bitcoin "ledger app" (or whatever that is called) after you entered your seed into the device.
Which is complete and total amateur hour.
In addition to that Ledger offers a service to "backup your seed": what could possibly go wrong with that uh?
I'm betting that we'll soon hear about hardware wallets getting drained due to the seed being exfiltrated through "randomness" in how transactions are built/signed (aka "kleptography").
And it's not just representative about people in the cryptocurrencies ecosystem: people simply don't understand computer security and don't understand the potential attacks nor the length at which attackers are willing to go to steal data/funds/ruin other people's lives.
At this point we've heard about chips' plans being modified before the chips are even built (only to lower the entropy of RNGs) [unrelated to cryptocurrencies btw], a worldwide backdoor attempt in SSH, eSIM sending secrets from hardware wallets with tiny attack surfaces.
You're not anywhere near paranoid enough.