If the hackers were able to push an arbitrary update it could have been much worse, they could have started silently collecting seed phrases to drain all wallets later