I did my own investigation because I obviously don't trust them.
What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO
@DocHex pretending to be someone else.
All of the following can be verified: