> This is only true for cloud based password managers
I agree, in the sense that one successful attack on the supposed centralized database containing all user credentials would have a high ROI.
But it also applies to local password managers. If 20 million people use the same password manager and I have an exploit for it, if I'm in the business of stealing data I'm likely to find a use for my exploit.