Because he wipes (writes to) the read-only USB stick? (The one that's had the firmware replaced with BadUSB, and which he then sticks in some other piece of hardware where it takes control of the machine and uploads his private key?
The largest vulnerability here would be the printer having some kind of memory, since BadUSB is a myth.
I'm not sure if they are serious or if they really do so. If they do, that's quite some dedication to security.
I certainly don't do that for the keys I use to access my home computer though.
Security is economics: what's it worth to attack you?
I can't be specific, but I'm pretty sure the data I worked with had very little comparative value.