Most hardware wallet losses among experienced users are not extraction attacks. They are approvals — signing a transaction whose meaning the device could not display. The Lattice1 attacks that problem directly with a screen large enough to render decoded contract calls, and a decoder that understands common ABIs.
SafeCards and permissions
Keys live on removable SafeCards rather than in the device, so the hardware and the secret are physically separable — useful for shared offices, travel, or keeping the signing device in place while the key is not. Programmable permission rules allow automation of routine signing within limits you set, which is unusual and genuinely useful for anyone running regular operations.
Practical limitations
It is a desk appliance: large, mains-powered and not something you carry. At around $400 it is among the most expensive devices here, and its firmware is only partly open. Setup is more involved than a plug-in device.
Who should use it
Active DeFi users, DAO signers and anyone approving contract interactions frequently enough that readable decoding changes their risk. For simple holding, a BitBox02 or Trezor does the job at a quarter of the price.