So there are three explanations:
1. Everything happened on his personal phone
2. He was logged into Signal on his personal phone to update the contact, and was also logged into the same Signal account on his government-issued phone. He imported the contact on his personal phone and then added it to the chat on his government-issued phone. From an infosec standpoint, this is not much better than #1 because he still has an unsecured device logged into the same Signal account that he's using for secure comms.
3. He was only logged into Signal on his government-issued phone and then manually copied the number into his government phone from his personal phone, not noticing that it was the wrong number. For anyone who has worked with users, this doesn't seem realistic. These guys have huge numbers of contacts, are very busy, and they do the most convenient thing possible for them. They do not sit around for hours copying information from one phone to another.
Let's assume that Waltz only used Signal from his government-issued phone and manually copied the number from his personal phone. He thought that the number he was copying was from Hughes' personal phone - it was in his personal contacts and he had been using it before either of them were in government. So even if Waltz himself was using a government-issued phone, which seems unlikely, he was simultaneously assuming that his subordinate was using a personal phone.
Even if you take the most generous interpretations you end up with the conclusion that NSC personnel were routinely using personal devices and accounts for secure comms.