It appears Rabbit had already released an update to address the issue on July 11th, the day before the author asked them for comment. They posted it here https://www.rabbit.tech/security-advisory-071124
> As of 11 July, we’ve made the following changes:
> Pairing data can no longer be used to read from rabbithole. It can only trigger actions.
> Pairing data is no longer logged to the device.
> We have reduced the amount of log data that gets stored on the device.
> The Factory Reset option is now available via the settings menu. Customers should use this option to erase ALL data from their r1 prior to transferring ownership.
> As of 11 July, we’ve made the following changes:
> Pairing data can no longer be used to read from rabbithole. It can only trigger actions.
> Pairing data is no longer logged to the device.
> We have reduced the amount of log data that gets stored on the device.
> The Factory Reset option is now available via the settings menu. Customers should use this option to erase ALL data from their r1 prior to transferring ownership.