(Threats to modify data on the drive or the code of its controller; not concerned with threats that fry the device with power.)
I can't really find a conclusive answer.
Signed firmware to prevent BadUSB-style attacks, price starts at $40 for 16GB, https://www.kanguru.com/products/kanguru-flashtrust-secure-f...
They have other models with signed firmware + FIPS 140 certified encryption + tamper resistance + physical write-protect switch.
They also sell an SSD enclosure with write-protect switch.
The marketing is a little too breathless to assure me that they did anything to actually make the firmware trustworthy: "Digitally Signed, Trusted Secure Firmware (RSA-2048 Bit)".
Signing something doesn't make it secure against exploits.
If you could recommend other commercial flash drives with signed firmware, they could be compared for security vulnerabilities.
Some models have FIPS-certified encryption, so they may have customers who are high-value targets, motivating attacks/testing for security vulnerabilities.
So I believe that it is an actual hardware lock, in addition to the os having the ro/rw status info.
If someone is interested, Kanguru have faster models than the one linked (which I have too), which is a little slow by today's standard.
https://eu.mouser.com/datasheet/2/268/MCHP_S_A0001038949_1-2...
Obviously if someone has physical access they could take the unit apart and circumvent this (but then they could flip the switch too)
Here's some exploits against flash controllers: https://www.bunniestudios.com/blog/?page_id=3592
Maybe someone can put in an epic weekend, to determine technical and market and logistics feasibility for a trustworthy USB flash drive product, in time to apply for the YC W24 extended deadline. From there, maybe Kickstarter to enthusiasts to fund the Mk. I manufacturing run. With Mk. I for experience and credibility, do enterprise marketing&sales, and/or SBIR to develop solution for possible sale to Federal gov't and contractors. :)