Yes, bitwarden has zero-knowledge encryption so it’s not a problem if data is stolen from the servers. However what if the hackers gain access to the server, then alter the website to silently send over my master password on login?
I have no doubt the servers are immensely secure, but it would be nicer if this attack surface didn’t exist. The bw staff could also be threaten by criminals to give access. With the incredibly valuable data residing on the bw servers, I think hackers/criminals will go to extreme lengths.
If I were able use the service only through the apps and verify their release with PGP/checksum, I would be better guarded against this attack.