It was never difficult to hold bitcoins. All you had to do was send them to an address you control with a long passphrase.
You invoke side channels -- what about these side channels: https://jochen-hoenicke.de/trezor-power-analysis/
If you insist that one should err on the side of being paranoid when handling money, you can argue that hardware wallets are secure iff you manufacture your own hardware.
Want true security without going into hardware manufacturing?
Pick a private key and write it down on a piece of paper (ideally you'd do it in your head) along with the corresponding public key. Then send bitcoin to an address that's controlled by the keypair you just created. If you did all the calculations in your head while wearing a tin-foil hat your bitcoin should be reasonably secure.
Your threat model almost certainly is one in which writing down a strongly-generated password is much more secure than anything else, if you take efforts to secure the written copy.
I feel like passwords are some kind of magical Wild West of crypto, where everyone has rolled their own and the "best practice" recommendations are often nonsense that ignores threat modeling and I'm just taking crazy pills for thinking we should treat it like other kinds of crypto where users only apply standard methods with verified entropy generation.