Earlier quoted context omitted.
Stealing Web Authentication keys from a hardware token is a significantly higher bar than phishing you or brute-forcing your password hash from a database leak. At the very _least_ the attacker would first have to compromise your machine with malware, at which point they could easily get access to all your password-protected accounts anyway with a simple keylogger.
What happens if you lose your hardware token (or it gets stolen, ec.)? Is there a way for then to access your accounts?
I really hope my Ledger Nano S becomes WebAuthN-compatible, as it can already be used as a U2F key.