The discussion doesn't explain why a stolen token still works after it leaves the machine it was minted on. Trust keeps holding. An old credential sitting in an IDE's local environment stays valid until 3,800 repos are already gone.
That's the part that doesn't sit right.
(4/5)