A hardware wallet keeps the private-key isolated. Your computer builds a transaction, the device displays the details on its own screen, you confirm with a physical button, and only the signature comes back.
The screen is the point. It lets you verify the real recipient and amount even if your computer is compromised, which is why blind-signing complex contract calls undermines much of the protection.
Buy only from the manufacturer or an authorised seller, never secondhand, and never use a device that arrives with a pre-printed seed-phrase; that is a well-documented scam. Generate the phrase yourself on first setup.
Related: cold-storage, seed-phrase, private-key, self-custody