That isn't "the unfortunate truth", the Samourai Wallet devs have agreed not to appeal so long as judge Cote sentences 5 years or less. Therefore, the plea agreement would not be brought before an appellate court nor would appellate courts take into consideration the Samourai Wallet plea agreement when forming opinions on other cases.
As for their servers, best practices would stipulate that they be encrypted. I'll admit I don't know with certainty but I am confident, based on Samourai Wallet following other best practices like purging xpubs at periodic time intervals and the fact that the government failed to access several of the confiscated devices, that there was no xpub exposure. Especially considering the large majority of users ran their own nodes, or used Sparrow Wallet, or used Keeper (or whatever that iOS app was called that implemented Whirlpool). IMO I do believe the xpub exposure risk was very minimal all things considered and I also believe that none of the xpubs in that risk pool were exposed.