There is a huge amount of vested interest in persuading people bitcoin or ethereum require no trust in third parties. This is not true, as illustrated by this case: the person writing code that’s supposed to secure your money made incorrect assumptions about security and was thus robbed. If you own bitcoin, you necessarily need to trust this person and his colleagues are neither malicious nor stupid. Why that’s better than making the same assumptions about state institutions and banks is, to me, not clear.
this seems more like it could be similar to a simple boating accident
It requires trust that third parties will act rationally in accordance with the incentives provided by the system, which is very different from trusting someone to custody assets for you.
At a larger level it requires trust that people will continue to see BTC/ETH/etc as being worth something, but that isn't a unique problem to blockchain based digital currency solutions.
And if you trust it to a safe in your bedroom, and your house burns down, then... ?
Which is more likely?
The hardware device is typically itself secured by means of a pin. Without the pin, the device can’t be unlocked so can’t be used, too many incorrect pin attempts will brick the device.
So the answers to your questions are:
1) If you entrust it to a safe deposit box then if someone steals it, it is worthless without the pin.
2) If the safe is itself destroyed and with it the device (this is also the case if you have it in a safe deposit box and the depository is burned down or something) then the private keys (and transitively the funds) can still be recovered using the recovery phrase. So if you have securely stored your recovery phrase and are able to retrieve it even this kind of problem won’t cause the accounts to be lost.
So what people tend to recommend is choosing good secure storage for your pin, keeping reasonable physical care of the device, taking the recovery phrase and splitting it into parts and storing those parts separately. If one of the parts is destroyed then you will need to urgently replace the hardware wallet, move the funds and securely store the new recovery phrase because if not you don’t have a fallback if the hardware wallet is destroyed, but otherwise you are good.
[1] https://medium.com/coinmonks/mnemonic-generation-bip39-simpl...
So if someone doesn’t have my wallet but has my recovery phrase they can regenerate my keys and brick my hardware wallet as it sits in my home safe??
Someone else using your recovery phrase to steal your private keys wouldn’t actually brick your hardware wallet. It would still work but obviously since the thing that it was there to secure (your keys) had been stolen that would be moot.
The subtext is that keeping all this stuff secure is hard and depending on your threat model may not be worthwhile. This is similar to the way in which for most people it makes sense to have a bank look after their funds. In the world of crypto though we’ve seen obvious examples of these centralised custodians being untrustworthy and since they are not regulated or FDIC insured or anything of that kind it’s much more risky.
[1] If you want the ability to recover your funds if the hardware device becomes inoperable, lost, stolen etc. If not you could just burn the recovery phrase so you don’t need to secure it.
Especially if you stored solid brick of gold instead of money
Since they're already practically minting their own dollars they don't need to steal yours.
And if for some reason the FDIC fails, then they effectively will have stolen your dollars.
It's no different from bank login in the end, once someone has it, it can be transferred at will.
Sure, the difference is that in banking system bank doesn't need your credentials to do stuff with money but even that when big crypto bois money are involved stops being immutable as DAO ethereum fork proves, fuck with important people money and nothing is sacred.
Bank login credentials do not confer undisputed ownership of an account. If someone unauthorized gets ahold of them, the bank doesn't throw up its hands and say "welp, nothing we can do now, the account just belongs to the hacker".
Pretty much this is what banks try if they can: https://youtube.com/watch?v=CS9ptA3Ya9E