In fairness to Obtainium, the signatures do match. Whenever you add an app via Obtainium (regardless of the source), it will only update the app if the signatures match. The trust is based on the signing keys, not the repo.
This seems right to me in theory. Catfriend1 could also have handed over the old repository and keys to a new maintainer. In fact, that would’ve been the sneakier way to do it, as we all might not have been the wiser. Ultimately, any app store is placing ultimate trust in the signing keys and that whomever controls them is trustworthy. The same thing could happen with apps distributed via GPlay (although handing over one’s Google Developer account might feel a bit more significant than handing over one Github repository).
That said, I got the 404 error from Obtainium, did a little digging, got wigged out, and blocked all future ST-Fork updates until things settle down. I’m definitely in the wait-and-see camp as well, since this whole situation seems unsettling. I wouldn’t be as paranoid if it were, like, a weather app, but ST has access to some of the most sensitive files in my life.
Open source maintainers are under zero obligation to all of us, but I do think it’s “the right thing to do” to honestly announce when you’re bailing and give users a heads-up (similar to what happened with the old, original version). Still, I really do appreciate all of the work that Catfriend put into maintaining the app during the last year.
Anyway, my point was more to defend Obtainium’s approach, which I think is reasonable. If the signing keys are compromised, all bets are off—and that’s true with iOS, Android, OSX, and even Windows (granted, with the more centralized app stores, the stores themselves can revoke keys that they think are suspicious, although they don’t seem to do a very good job of that). That’s why supply chain attacks are so potent.
I hope things do settle down, because ST is one of my absolute favorite utilities, and being able to run it on Android is one of my favorite parts of Android.¹ I wish I had the time to contribute. 
¹Although it sounds like the OG app still does work (especially turning off global discovery and relays would help reduce unpatched attack surface), and it seems like we could run ST inside of Termux (or even the new Linux virtual terminal) as a less-elegant alternative.