Bitcoin addresses (private key) is secure by randomness.
The odds of someone guessing a properly random bitcoin address (like satoshis) is immeasurably difficult and very unlikely.
The hardware wallet is a machine to create that randomness, but as you probably saw in the case of cold card, some devices fail to be random.
There are a number good ways to generate a random address though including using the bitcoin software directly.
