That reasoning strikes me as flawed. It would be like submitting a term paper to a teacher after he proofread your draft, with all of his suggested fixes, yet his final response is "Oh sure, you fixed all the problems I found. But I found so many before, what about the ones I didn't find? C+"
This was a third-party audit, and VeraCrypt fixed all of the critical ones that they found. All software has bugs. To find some that are critical is not necessarily indicative of the quality of code on the whole.