Even hardware wallet users aren’t safe, and funds aren’t secured anyway.
It seems that with any financial assets, there is no 100% guarantee of security; risks, however small, always remain. In the case of crypto assets, however, the risks appear even higher due to the intense scrutiny and frequent attacks by malicious actors. These HW devices are no longer merely storage solutions for crypto assets; it have become an attack vector that will be targeted with increasing frequency (especially as the asset's price rises) because the stakes are higher, making the effort worthwhile for attackers.
I know this happens from the supplier chain, but it has become very hard to trust any hardware wallet nowadays.
Therefore, when purchasing a HW device, you should factor in the possibility that it could be compromised, rather than blindly trusting the manufacturer or seller.
Therefore, one should not forget about risk diversification.
Although I bought my Ledger from the direct Ledger store from Amazon, I am still feeling risk.
Even if you were to buy the hardware wallet right at the doorstep of their production facilities, risks would still remain.

I am out of my home on vacation; after reaching home, I have to check everything.
Don't forget to open the HW device's casing and check the circuit board for any visible foreign objects (it seems every new buyer of these HW devices should make this a standard practice now

). So far, malicious actors haven't figured out how to disguise them effectively.
I am not sure about my funds, although there is a small amount.
There’s no point in unnecessarily working yourself up into a state of fear. Things might just turn out okay after all. Although, knowing Ledger, it’s probably only a matter of time.

Maybe it’s time to consider switching to hardware wallet from other manufacturers?
I bought the device long ago and from a real source.
This could prove to be your salvation from the ongoing hacking.
These hardware companies shouldn’t assign any suppliers; they should only sell the device from the website and deliver themselves.
What about even eliminating the intermediary - the postal service or delivery provider (which, incidentally, represents yet another attack vector)? That’s simply not feasible, as setting up an in-house delivery service makes no economic sense.
By the way, manufacturers don't ship their devices to every country (even where postal services are available).
Not sure if the delivery companies also try to temper the device, but they have to check everything and verify the device.
Just because a vulnerability hasn't been exploited yet (like the 5 year period in the case of Coldcard) doesn't mean it won't be exploited in the future.
The manufacturer should have some system to verify whether the device is tempered or not.
Trezor, for instance, has this protection - a sticker on the casing.

By the way, as far as I know, Ledger never used anything of the sort, but times have changed, and the presence of "new integrated components installed by malicious actors to steal funds from wallet owners" will force the implementation of new measures.