Multi-vendor multisig.

This is the way. Don't trust one hardware wallet manufacturer. Don't trust one signing device. Spread your keys across different vendors—Ledger + Trezor + Coldcard, whatever combo works.

Single points of failure are how you get rekt. Supply chain attacks, firmware backdoors, vendor shutdowns—all real risks. Multi-vendor setup = you're not betting your stack on one company's security.

If you're holding serious bags, this should be standard. Not paranoia, just basic OpSec.