Although I agree with your argument, the critical and most important thing to note is that we're talking about mobile wallets, which are only as secure as your ability to prevent your phone from being lost, stolen, or unlocked. Any mobile wallet should be considered the same as having cash in your pocket. If you can't afford to lose your leather wallet and $20 cash, don't have more than $20 worth of BTC in your mobile wallet.
Taking that to the next step. Should be, any "hot wallet" that is not securely encrypted with a very safe encrypted backup.
It's nice that I have a PC in my house with a full node on it that has BTC on it.
It's secure in the fact that it's an Intel NUC ( https://www.intel.com/content/www/us/en/products/boards-kits/nuc/mini-pcs/nuc7i3bnhxf.html ) that unless you know where it is even if you rob the place you are probably not going to find it.
It's secure in the fact that it has a somewhat complex password on it that with current computing power and BTC price it's going to cost more to crack it then it's worth.
I have a backup of the wallet.dat file in a secure location with some other documents and recovery stuff.
But to say it's REALLY secure is a stretch. It's secure enough that if it does get stolen I am out more for the cost of the unit and the drive then the BTC I have on it if they do manage to actually crack the password before I get to the secure location and move it.
If my leather wallet with $20 get's stolen then I am out the cost of the wallet and the $20
If my phone get's stolen then I am out the cost of the phone.
Because I have the recovery words someplace safe and..the phone is pin / fingerprint protected and the wallets are both password / fingerprint protected and I can remote wipe the phone.
The security of the phone and PC are both moot however, if we go back to the original thought of what happens if the wallet software itself is compromised.
So multiple layers people. Hardware signing only for wallets with large amounts, cold properly created offline wallets for storage and hope that the hot wallets we use day to day with non critical amounts are properly written.
-Dave