Point to literally anybody on the development team who claims it can stop a small team of professionals with a 10 M$ budget from finding a remote exploit. That is a tiny fraction of what a state actor can deploy and constitutes at best a low-end attack by a state actor who is actually targeting you. Just for reference, we can peg that at a first-order estimate of 40,000 person-hours or about 20 person-years, so a team of 20 with a whole calendar year to work full-time on finding a remote exploit. Even the developers themselves do not think they can provide protection against such low-end attacks.
I mean, seriously, find me a single person in the entire world doing offensive cybersecurity research who thinks there is any system in the entire world that can stop any team with a 10 M$ budget. Find me any single person in the entire world doing cybersecurity that would place a open bet that they could stop any team with a 10 M$ payout. I am certain you would be laughed out of the room in the former, and you would see dollar signs in their eyes if you introduced them to the latter. Stop propagating marketing fluff.
That is not to say that Qubes is horribly insecure. It is just not even close to "virtually impossible to break". And, to their credit, they are honest and very clear about this in their messaging and should be applauded for it unlike actual bad actors like Crowdstrike, Microsoft, Apple, Palo Alto Networks, Google, Sentinel One, (basically everybody) etc. who just make up whatever security bullshit to push product. It, however, does no good to make up random hyperbole with no basis in fact for products that are actually being careful to not overpromise. Frankly, it is doing the team at Qubes a disservice because people will hear the nonsense and then get burned and blame Qubes even though they were careful to honestly express the limitations.