They’ve known about it since 2016!?!
They’ve known about it since 2016!?!
It's much more likely that an employee's account was compromised and then used to sign malicious APKs, or something similar. Once Samsung realized, they could get the logs of every APK signed with the HSM and then revoke those certificates individually through a software update. Not really sure if they actually did that or not, but either way the key doesn't necessarily need to be replaced.
Android doesn't really do revoking certificates in this way. The only way to fix a leak of a system key is to generate a new key and use replace the entire system image.
I hope you're right that this is merely a remote signing account being compromised, because I don't see Samsung building six years of new system images.
The app-signing key can't be changed without just creating a new app, and creating a new app means you users won't be able to upgrade - they have to manually uninstall, go to the app store, and install the new one.
It's not just an app store thing, I think I remember Android itself verifies that the upgrades have the same key as the old version.
https://source.android.com/docs/security/features/apksigning...