The Anti-Exfil protocol also originated from
@Blockstream and they developed the first production-ready code for it.
Anti-Exfil protects you against private key (or seed) exfiltration via signature nonces.
A dishonest hardware wallet can secretly hide tiny pieces of your private key inside the “random” numbers it uses every time it signs a transaction. Over enough transactions, someone watching the public blockchain can put those pieces together, recover your key, and steal your bitcoin - without you ever noticing anything wrong.
Only two HWWs have this implemented:
@BlockstreamJade
@BitBoxSwiss (they call it Anti-Klepto)
@Blockstream and
@adam3us have been protecting you from this class of attacks since 2021.