"....there are a lot more users trusting them with their xpubs than users that don't" That's not quite true according to their numbers. https://blog.ronindojo.io/most-whirlpool-users-run-dojo/
That's Whirlpool. Their wallet users are easily a different story, considering that their default marketing posture is as a "privacy" wallet, downplaying the fact that its really only a privacy wallet if you know how to operate their server . Samourai didnt even have Dojo for years, and everyone just basically had to trust Samourai wasnt doxxing their xpubs.