If someone compromise bitwarden infrastructure can (and probably will) silently release a "new" minor version of app and webapp so that every master password is sent to him, and then decipher passwords.
It will last only some hours at worst but will still collect a lot of passwords.
That's only thing I'm worries about, but I still use bitwarden as I think my passwords being compromised in this evenience as nearly impossible