So yes, it is a serious accusation that points out their consistently lax programming techniques when it comes to security.
The problem was that one of the parameters they used in their ECDSA signatures, k, was the same at least once. This allowed the key to be computed with simple math, but the generation of the key itself was not the issue.