When vaults are stolen by breaking into the cloud, the attacker has unlimited tries to guess the correct master password. This is called an offline brute force attack. With heylogin, the attacker has to physically steal the security chip and only has a limited number of attempts to guess the correct PIN. With iOS, for example, the attacker has 9 attempts before the device blocks completely.