One option (if you have a trusted FPGA) is to run something from opencores.org, where you can verify the code.
But more generally, yes there is an issue of having an initial base system which can be trusted to some degree.
But more generally, yes there is an issue of having an initial base system which can be trusted to some degree.