use a non-infected device in the first place, (do a secure erase before using it) then you're fine to use your usb even online
you don't need to buy expesive HW like trezor, just be vigilant and don't download random stuff from the web
my hotwallet was never hacked, and i've done with it plenty of transactions
while this is true for someone who knows what he is downloading and doing online (you), it is untrue for technically-unsavvy people which OP probably is. so my advice is always:
buy a hardware wallet. there are cheap ones too.
@Towelielie
good choice. have fun with it.
