::
It’s because the accounts and addresses are all derived from the 24 word recovery phrase generated at the time that you set up the device.
the specific BIP39 mnemonic standard, which the 24 word recovery phrase is created from – is technically impossible to crack (even with intense computational brute forcing).
also the device can generate a virtually-infinite amount of 24 word recovery phrases, and so this process isn’t 1 an done. you don’t use a ledger once then throw it away if it’s compromised. u can reset it, generate a new 24 word recovery phrase, and the device will literally be brand new and absolutely secure.
this is all based in cryptography, math, RNG, and people who have dedicated their lives to designing these systems (long before the existence of hardware wallets, and even cryptocurrency).
with private keys, we’re talking about cryptographic research dating back decades and decades and decades. I wouldn’t be worried : )