How OBOL rates hardware wallets
A signing device has one job: keep a private key somewhere software cannot reach it, and show you honestly what you are about to sign. Key isolation therefore carries the most weight, followed by firmware openness — because a security claim nobody outside the company can check is a marketing claim.
Recovery design is weighted equally with openness for a simple reason: far more crypto is lost to bad backups than to attackers. We favour standard seed phrases you can restore on any compatible device, and we mark down schemes that make the vendor a necessary party to getting your funds back.
The blind-signing problem
Most losses involving hardware wallets are not extraction attacks. They are users approving a transaction whose meaning the device could not display. Devices with larger screens and proper transaction decoding get credit here, and devices that show you a hash and ask for confirmation do not.
What a hardware wallet does not protect you from
It will not save you from signing a malicious approval, from a compromised recipient address, or from writing your seed into a phone. It protects the key, not the decision. Every score in this category assumes you still verify addresses on the device screen.