I use this functionality on a near-daily basis, and received an email from GitHub this morning informing me that two of my older, backup SSH keys generated on Yubikey 4s had been revoked. I'm going to start the replacement process with Yubico this morning, and probably share my experience with it here.
FWIW, I went through Yubico's automated replacement process earlier for a couple of Yubikeys. It took just a moment, was pretty much fully automated, and worked perfectly.
They gave me a coupon code, I went to their online store, and ordered the replacements.
The whole thing took maybe five minutes from start to finish.
Unfortunately, since I had previously overwritten the factory OTP configuration, I had to take photos of my affected Yubikeys, including my email address in the photo. A bit longer, but still easy enough. Now to wait, and hope they don't deny my claim (despite having ordered them directly from Yubico in April of this year...)
Update to this: I submitted a photo earlier with both of my affected keys, and I just got an email back with a coupon code good for both keys, with free shipping.
As bad as this might have been, Yubico seems to be doing a top-notch job of covering their customers.
Same. Replaced around 6 Yubikeys, some of which were associated with GitHub. Fairly seamless replacement process (but have obviously yet to recieve the replacement keys yet..)
Shitty situation, but good response from both GitHub and Yubico.