In talking to people smarter than me I think there’s two points 1) since the Samourai backend is proprietary it is unknowable if there was a honeypot. They could’ve had good opsec and purged xpubs after using them or kept them forever. Impossible to know unless/until it comes out in court. 2) someone somewhere has to collect xpubs to coordinate the transactions. Oversimplifying: So your options are basically central coordinator or run your own(they called this a Dojo). Samourai provided both options. User had to elect not to run their own Dojo and divulge their xpub, it was not required. People should never give up their xpub imho