Heartbleed was in production for two years. Log4Shell was in the wild for 8. ShellShock for 20. The fact that some exploits are discovered quickly is not in any way a proof that nobody can get away with it. You may argue that these vulnerabilities are unintentional. I would say distinction without difference.

Yes but this is discussing deliberately injecting malware into an open source project, which differs from exploiting a vulnerability that exists in one.