I wonder if these risks are also with a service like 1Password. How can you know if they are in fact, actually encrypting every single detail associated with the login? It’s not like we can view the servers ourselves.
So a hacker would have to get hold of the encrypted data, together with the secret key for each account. The secret key isn't stored by 1Password, requiring the hacker to brute force it. However, each key provides 128 bits of entropy, which makes it infeasible to brute force with current technology.
More info: https://support.1password.com/secret-key-security/
Although it's possible they implement this with a local bloom filter or something. I'm just speculating. And either way, those requests would only end up stored in some server logs somewhere, rather than in a database row directly linked to your vault.
EDIT: It is in fact done locally. :) see: https://support.1password.com/watchtower-privacy/