The frustrating thing to me is that this guy will get this solved and we’ll all move on. He’s reasonably well known and had enough Twitter juice to get attention. All the small people who end up in this situation, whatever it truly is, without those resources will remain screwed.
On the other hand this is like not backing up your hard drive. Having a single point of failure and expecting anything less is...
Like you said, he's big enough to shout into the abyss and get a response, while others have to accept that a single point of failure is exactly that.
If we changed the headline to hacker deletes '5 years worth of work', the response would be different; two-factor should have been enabled, should have used a strong password, one password per account, yubi-key, etc. The onus would have been on the developer.
There are plenty of free hosting services for repos, so there's no reason IMO to not maintain a mirror.