First of all I haven’t done any HDL (Verilog, VHDL…) programming so I just know what is it…
For instance Linux is open source and the software is totally under your control so you can totally trust the software developers.
The thing is what if the hardware was the problem? How do people trust the hardware developers??
Couldn’t malicious things be done with HDL?
It's hard to prove that hardware wasn't tampered with at the factory and in fact it is absolutely routine for hardware to come with "backdoors" such as boundary scan implementations, unexpected ways to read out firmware, etc.