So you're claiming that an adversary can:
One identify that Bitcoin exists on the device
two figure out when the device is active
three remotely connect to the device
four exploit the device to extract the secure Keys
without user interaction
that is an extremely heavy lift and verges on magical thinking
