That might have been true a decade ago. But GPUs and FPGAs have long been obsolete for mining Bitcoin.
Mining is happening on custom silicon in large-scale operations. They specifically observed several of those large-scale operations in multiple nations and extrapolated out. I don't see how that methodology is flawed.
They do. Even back in their pre-UEFI days, it was possible to flash BIOS from a properly-formatted USB drive by holding down a magic key combination at power on. But it was not exactly publicized as a supported method.