I feel the author's frustration with the spec. I think that the OAuth2 spec could do a better job of outlining best practices and security, but calling it a terrible spec over the potential of poor implementation isn't right IMO.
Also, stealing an access token is far from "Game Over', as the author states. They're short lived and meant to mitigate the damage done by having one or even several leaked. Getting your hands on a Refresh Token would be closer to "Game Over". Although even then, it'd be trivial to have the compromise reported and expire the Refresh Token of that client and subsequently all access tokens.