Thats awesome. Personally there are two top keys on the market. The google titan key and the yubikey
Its not really reduced in todays era. Linux is just as attackable in numerous other ways. The traditional malware is reduce yeah.
thats great mine are stored in VaultWarden. You know what keeps my mind realizing that this is a false sense of security? Its that you are only as strong as your weakest link. In this case my bitwarden password but I used FIDO2 on the password vault as well so you cannot sign into my vault warden without my yubikey
So my suggestion is to move from keypassXC to VaultWarden (self hosted bitwarden docker, coded in rust). This allows you to protect your vault with your nitrokey
Perspective: I did it for convenience in addition to security. Its nice to have a physical chip that you must insert and type the pin to in order to connect to an SSH session. It secure the SSH session away from a key stored on the system.
I created this thread to show that the YubiKey is the key that can do it all. Not that it is the only solution. My perspective is that if I was in the market for a key today it would be the yubikey that wins. Convenience is often as important as security. However given differences in setup it may not be the best decision for you.
Totally up to you and at the end of the day its only 45 bucks