The Coldcard hack was not a vendor looking at anyone's private key - it was weak randomness that made some keys guessable by any attacker. Ledger's optional Recover feature raises a closer version of the same question: whether pieces of a user's key ever leave the device to anyon...