YubiKeys are non-upgradable by design. This is occasionally annoying when new standards come out and you need to go buy new keys (which is not something that's gonna happen a lot), but it significantly reduces the attack surface of these devices. They've been pretty good about giving out free replacement keys whenever major flaws have been found, and webauthn is pretty good about remaining backwards-compatible with U2F keys, so I don't think it's something they handled particularly badly.
I get that, but my point was that they just released expensive new products knowing they'd be obsolete in just a couple of months and people will have to throw old ones in the garbage and buy new even more expensive ones. I do not doubt that a product with an immutable core and mutable interfaces is both possible and even more secure as when flaws are discovered (like last year), some may decide not to replace them - even with free replacement. I spent over $100 just last year, and I think this is a bit too much. I give my old keys to my kids, but, still, I'd appreciate some form of subscription service, which both reduces my recurring cost and possibly improves Yubico's bottom line, too, primarily by building loyalty instead of pissing customers off.