How could it negate that? You keep your secrets yourself and need a backup in case the hardware gets broken or lost. That’s not the difference between a hardware and software wallet. The difference is that the secrets are never on a network-connected, potentially compromised device and that the hardware wallet asks you for confirmation of every single transaction.
Most attacks that we see are tricking the user into giving away their seed phrase, and most of them by posing as fake support in direct messages on different social media channels. Sometimes they use fishing sites in the design of a specific wallet app, which is made a bit easier, when the wallet app itself is browser-based, but most of the times they save that effort and very generic fishing sites for all wallet apps on all blockchains are already sufficient to persuade enough victims.
In a lot of aspects, the difference between Daedalus and browser-based light wallet apps is not that big:
- Both store your secrets encrypted by the spending password somewhere on your computer and malware could get at it if it can access your disk.
- Secrets are never transmitted to the server, but only stored on your machine (in the browser’s storage in the case of browser-based wallet apps), but as an end user you can hardly verify that (again, not only for browser-based, but also for Daedalus), but have to trust the wallet app creator.
- For all of them, you should make sure to only get them and their updates from legitimate sources, which is not as trivial as it sounds (there have been fakes in app stores for all of them – including Daedalus), but also not that hard: Get the links from the official website and make sure that it is the official website by looking at multiple sources – https://developers.cardano.org/showcase/?tags=wallet, this forum, Twitter, Discord, Telegram, … I have seen scams that scaringly convicingly faked one of those channels for a wallet app, but never all of them.
Altogether, the big difference is not Daedalus vs. light wallet apps. They can all be rather safe if your machine is not compromised and you don’t fall for scams. The big difference is hardware wallet vs. software wallet turning “rather safe” into “pretty safe”. … and that only if you never put the hardware wallet seed phrase on a computer and don’t let them trick you in doing it, nevertheless.
This is all not a speciality of Cardano doing it significantly better or worse, but pretty much the same for all cryptocurrencies. A case can be made that this is not usable for the majority of people and they need a help desk that can suspend their account, reverse transactions, and reset their password in case something bad happens. But that then is a case against cryptocurrencies in and of themselves.