Understandable; I realize you posted in the Sequoia Community but my eyes are generally drawn to the profile information first.
... on an older system with no touch ID, it's possible for a user to have a blank login password. In that case, the Passwords app would not require a password for access and the treasure chest would be open? Ooops ...
Yes that is plausible. I know that it was possible to create a User Account with no password a long time ago, but I have tried and failed to create a User Account with no password on Macs for any recent macOS version. I have been unable to circumvent that requirement. Automatic login sure, but a completely blank / empty password... no.
I suspect that if one were to sequentially migrate a User Account — one created a long time ago, one with no password — to a newer macOS version, Migration Assistant would not object to that lack of a password. As time goes on and macOS programmers eventually become replaced though, it becomes increasingly likely a bug will arise that would manifest in some kind of unpredictable behaviour. Or, a security hole as you describe.
Passwords are considered "normal" and as time goes on it might be totally inconceivable one could have a User Account without one. As you say... oops.
What's worse is that Apple is already considering passwords obsolete in favor of biometrics and passkeys. Can't say I disagree with that.