A master password is the only pw in a PWM at real risk of reuse.
However, without placing too much unwarranted trust in the user, consider the following:
- extensive warnings during user onboarding about how to approach setting and safe keeping of the master password, especially around reuse.... ok, but some users are still hopeless with this, what then
- taking Lastpass for instance, lock-out features for logging into the extension if you're coming out of a new geo-ip (proactive risk control)
- taking LP again, alerting to the user for successful logins to the platform from new geo-ips (reactive risk control).
- all the on-device security controls required to get into a PWM: touch/face-id logins for the apps, an official browser extension, on and on. I'd also imagine LP security is watching HIBP very closely.
Put all that together, odds are you or the PWM security teams are able to filter pretty well for password reuse for master passwords. So yes I'd expect sources/stats to be out there, or at least counterpoints to the above which when put together map a decent defense-in-depth for PWMs which isn't present in most or almost any browser extensions, to include Tier 1 cryptocurrency browser extensions which are responsible for significant more funds and still maintain good security (think: Metamask).