A lot of tagging programs add them as they just get appended or prepended to the file regardless their content. Sometimes one program reads a format but writes in the other, I have personally found a FLAC in the wild with ID3v2 at the front, ID3 at the back (corrupt) and FLAC metadata as well. The FLAC metadata inside was wrong, the valid one was outside at the front (sadly it was a broken JIS encoding).
There is no sane approach to media. Between legacy formats, legacy tagging, and all kinds of implementation specific bugs, you are in for a ride if you want to cater to more than one decoder out there :)
Still flaky with double ID3 tags (front/back) or issues parsing metadata (so it fails decoding), but the issues with variable block size were solved. Most FLAC I handle on a large system play fine.
There are other issues related to streaming the FLAC via Range requests depending if it is WebAudio, <audio> or directly in a tab, however this applies to all audio/media in general.
I use a Ledger for U2F/WebAuthn/GPG/SSH. Works pretty well, you can have multiple entities from a single seed. You only have to backup that seed (which can have attached passwords), and it can be recreated across any compatible device (Ledger, or Trezor, or even decode them manually)
To add to the previous response, for your wallet you can create multiple sub-accounts or sub-addresses, that can be used to specifically track payments. You can also use integrated addresses, which tags an encrypted payment id to go with it.
Additionally the sender can prove they sent a specific transaction output to you, without exposing information where it came from.