Re the final point: Was it like this from the beginning? I still have some identities signed by my original PGP key with which I signed up to Keybase https://keybase.io/azag0/graph
yes, but to be clear: an identity proven by your PGP key is still considered "you" for chat/KBFS, as your device keys have transitively said that PGP key is you. So (1) PGP proved twitter (or whatever), then (2) PGP signed in a device key (which counter-signed), and therefore (3) device key can read KBFS/chat that is sent to you by your Twitter name.