I don't think BIP85 or passphrases protect you in case of malicious firmware
Nor malicious hardware
reply