I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
This should not in anyway makes you look less on hardware wallets still.
The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.

The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
- let's start considering passphrase with recovery seeds.
- let's start considering multisig if possible.
- let's start considering the Dice 🎲 rolling method for entropy
While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.