Even if the compromise wasn't on the developer's machine, it could have enabled a supply chain attack post-deployment.
Holding that much money on a machine that is not ultra secure is borderline insane.
It's similar to how many crypto businesses will have a hot wallet with some fraction of their more secure cold wallet that they're okay losing.