And as far as I understand he's now describing his methods there rather than particular attempts?
Choosing a random new key invalidates all your existing credentials enrolled with that Yubikey, since your Yubikey will no longer be able to decrypt the identifier provided and sign proof that it knows the associated private key (in practice what it decrypted was your private key for that account, and now it can't do that)
This "reset" operation is supported on Yubikeys, and you perhaps should do it when you get the key (Don't do it now! It invalidates your credentials as I described!), although most users probably don't. However, even if you do this if your key is fake why would the initialisation actually work? The same adversary could modify it to just ignore this reset attempt and use a symmetric key they know. So there is no benefit from hypothetically requiring you to perform this initialisation step, nor from having the device do it when first used.
Hiding such symmetric keys (typically AES) from adversaries with fairly large budgets who have physical access to your device is already a thing. Would I bet my life on it if I was Edward Snowden? Maybe not. Am I comfortable with this for securing a bank account with my life savings in it? Yes.