If the password manager server is hacked and compromised, then syncing your passwords with the compromised server will lead to compromised passwords (duh)
No, not "duh". The right way to do this is client-side encryption/decryption. The server then does not at any moment know anything about your passwords.