They could have easily rolled an update that forces a seed refresh. On boot -> if seed exists -> prompt user to confirm they have existing seed words / verify that -> generate new seed -> ask user to migrate all funds to new seed (now on device), load old seed in memory transiently to allow signing the migration tx.
This is more jank tha it should because they don't have a first-party app. Something like Bitkey handled something similar in literally two clicks during the privacy upgrade update (which required a new 2-o-3 to be generated.