Earlier quoted context omitted.
[flagged]
In fairness the dev is a 16 year old. It’s still bad practice but this is a minor mistake all things considered compared to most programming projects by people of that age
Unfortunately, nobody else seems to either, which is why my comment is getting downvoted.
"Why is this a problem?" say people when the publishing of a private key is inherently the wrong thing to do, and will always lead to a bad consequence.
It doesn't matter who's key it is, how it was generated, how it was obtained, etc...
The purpose of private keys is to be kept secret. A published private key by definition is worthless. That will have a consequence. Either it'll be make-believe fairytale security, or someone else getting into your product, or what happened here: the third party who's keys were stolen changed the locks.
Meanwhile I'm at -4 and clocking down because people struggle to understand how keys and locks work, never mind cryptography.