Has anyone actually seen personal SSH or Git signing keys get stolen and used in attacks (not counting servers sitting on the internet with ssh open) ? It seems like the only really useful purpose for these tokens is as an MFA token, because passwords just suck. At the same time, it seems like long random bits that can't be remembered by humans just aren't so vulnerable that we need to carry around something to unloc…
If an attacker can exfiltrate your private key they can probably keylog your passphrase & your VPN details
PIV/GPG smartcard solves he former and 2FA solves the latter so something like a yubikey/nitrokey gives you both in one device
Anecdotally I do have a friend who had his private key & passwords pilfered which was noticed when someone tried logging in from some other country.