The argument I've seen provided for this is that an attacker would both need your password and physical access to a device with 1password already set up on it.
To use 1password on a new device, you need a "secret key" that is provided to you when you create your account which serves as a basic form of 2FA for your whole account. Not a perfect system, but it is not as simple as just getting your password and having access to everything.