AV companies have a lot of behaviour analysis/decoding/parsing done inside their code that is as important as their "static" signature set.
In fact, I would say that having access to the code and how they analyze the files/memory/etc is more valuable to a competitor (and the "bad guys") than the static signature set.
I admire you for building a business on cleaning up hacked Wordpress installs (seriously), but that's not the same game that Kaspersky is playing.
From an industry point of view its always the DB size that matters. When MS bought Giant it was due their DB size, it was huge and useless e.g there were installers that generated random guid for active x controls, registering those guids as a signature was pointless but they still went with it, when it was time to sell the MS guys fell for it. I worked for a company that was sold eventually and it was the same story when the founders decided that its time to sell it was all about the number of signatures.
Kasperskey are known to have a brilliant engine, this leak is a huge blow for them
On a different note: I wonder how this happened in the first place, the security companies that I worked for were pretty strict on code access, I couldn't checkout any code I wish, only a few people could pull the entire code repository.
It's also possible to do some source code analysis to identify vulnerabilities in the product that might not be otherwise fairly easily exposed.
The virus signature database is pretty much worthless for all but the lowest hanging of fruit. There are plenty of tricks botmasters use to get around signatures, and AV firms are moving (or have moved) to more behavioural characteristics to detect malicious code. It guess it all depends whether that's in the updates or in the code base.