YubiKey is still selling old stock with vulnerable firmware

YubiKeys are unfortunately still the best option, just make sure you are buying a key with firmware version 5.7 or later. They support the most modern CTAP versions which for example enable the key itself to require a FIDO2 PIN be used.