If you consider it to refer to the supply chain attack, well, OpenBSD is too minor a platform for anyone to consider it worthwhile trying to invest in the long supply chain attack for the OS.
If you view it as the break-xz-to-attack-sshd, OpenBSD is designed as a single system with a single codebase, and has a general aversion to features such that it is difficult for an undersecured random library to become a vehicle to breaking a major, important component.
If you view it as the techniques used to publish an exploit in open source code, well, OpenBSD is filled with the kind of developers whose self-confidence is such that they believe that they are uniquely capable of writing code without those kinds of issues and will denigrate the use of newer technologies that mitigate that risk with the attitude that it coddles programmers and coddled programmers aren't good programmers. Or, in shorter terms, OpenBSD is actually one of the projects I'd expect to have a relatively high chance of a clever contributor being able to smuggle in an exploit in plain sight.