Assuming you mean password manager services. If they can get a copy of the vaults at all, in a well-designed system they have to attack each one individually.
They also serve business use cases for sharing, and revoking access, to other services.
> So, why don't people use local password managers?
Because synchronizing between devices is an important factor in usability, even just for an individual, not even considering groups or businesses that would share access.
Local password manager vaults can also be stolen by malware, would result in the same catastrophic loss you suggest.
> Just a txt file encrypted with "master password" should be pretty damning to break into. And the reward for breaking in would be password for 1 person. (compared to 100k businesses).
Password managers do just "do the thing you'd want them to do", and because they have a well-defined use case, they can support extensive discussion about threat models, and can easily and coherently support lots of people benefiting from the best research and security, without each having to individually roll a solution.
A hosted service without persistent compromise is likely less vulnerable to an old copy of a vault, and an accidentally disclosed master password causing catastrophic failure.
Lastpass has some issues that look egregious in retrospect. The early exceedingly low-strength vaults that were never upgraded (only possible on login).
1password publishes research and pushes forward authentication management beyond password, e.g. passkeys, in a credibly cross-ecosystem way.