Earlier quoted context omitted.
That's one thing that might happen. Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).
Which of the two outcomes do you prefer to happen: 1. True malware creator and seller is sent to prison. 2. True malware creator and seller is not sent to prison. Whether he pleads guilty or not has nothing to do with him being a security researcher. I'd much rather have more false positives than false negatives. You, and the rest of Europe, would too.
Unless of course you're so mediocre that you'll never ever risk doing anything even remotely significant; in which case, whatever.