hypothetically, the pi-hat is loaded with special package that updates the system on your sd card once you plug it in. Then the seedsigner you're running (altered) would itself alter your transactions, man in the middle style, and hope you don't notice before broadcasting it?? Unlike a Trezor the sd card system is not verified on the device, only before you write to the sd card on the main online host computer.
Multi-sig which is the main use of this device, IMO, an air gapped multi-signing tool, would notice this alteration before signing the next part (unless your host system was somehow also altered with the same attacker's binaries, almost impossible to do that with supply chain)
