I think the best place to secure our coins now is the software non custodial wallets. Since the hardware wallets are prone to attack.
Every wallet is prone to attack, even the software wallets we sing their praises have been attacked several times in the past.
e.g, dating back to 2018, Electrum was plagued with phishing scam where hackers use dummy nodes to imitate electrum servers and if a user connected to their server tries to make a transaction, the scammers send false error messages directing those users to update their apps with an embedded phishing link.
Wallets are continuously under attack and that's why they rollout consistent security updates.
This discussion is not a case of wallets being attacked but that of data breach in the shipping service which delivers these wallets to clients after purchase, they're actually different concerns.
This is so sad, isn't this enough for Trezor the take legal action against ShipMonk?