That's blatantly understating how many packages are reproducible.
Multiple people can grab the sources from the developer, review and apply the patches, build the package and publish the resulting hash. With reproducible builds, all people end up with the same hash, which should also be the same for the pre-built package in the repository.
In other words, instead of trusting one single person (the maintainer) you split the trust across multiple people. This is definitely an improvement thanks to reproducible builds.
I am curious what are good solutions to this problem? Compile your OS (and any other software) from source?
You have to rely on a distribution that has a many-eyes review policy and has security conscious users.
And, there are large tech firms doing this already.