The threat it removes
Key extraction. Clipboard stealers, infostealers and compromised browser extensions can read a software wallet's encrypted store and attack the password offline. A hardware device never exposes the key material to the host at all.
It also enforces a deliberate physical step. Every signature requires a button press on the device, so nothing can be signed silently in the background.
The threat it does not remove
If you approve an unlimited allowance to a drainer contract, the hardware wallet will sign it, because that is exactly what you asked for. If you send to a poisoned address you copied from your own history, it will sign that too.
The device protects the key. It does not protect the decision, which is why reading the screen it shows you is the entire remaining defence.
Clear signing versus blind signing
A device that can decode the transaction shows you the token, the amount and the destination. A device asked to sign an opaque payload shows a hash and nothing else — that is blind signing, and it is where most hardware-wallet losses originate.
Prefer wallets and chains where the device can display a human-readable summary, and treat a request to blind-sign as a reason to stop and verify independently.
Buying and setting one up
Buy directly from the manufacturer. Supply-chain tampering with a pre-seeded device is a documented attack, and any device arriving with a recovery phrase already printed is fraudulent by definition — you generate the phrase, it does.
Set a PIN, generate the phrase on the device, verify it on the device, and store it as physical media. FBT Swap connects to hardware wallets through your wallet application, so the signing step happens entirely on your device.