Most of it is implausible.
Are fleets of 100s of Rokus used in commercial settings? A quick google suggests no.
Do fleets of commercial network devices typically implement some weird peer-to-peer leader election thing to... save some bandwidth on updates? Also no, centralized management service/console is both way easier to implement and a desirable feature to boot. Chances are that's how device fleets are managed in places you've worked.
Then what is 'a quarter mil in CDN fees'? Once? Per update? Per month or year? Oddly specific details like this are often a hallmark of a tall tale and this one is both oddly specific and oddly nonsensical.
We also have to believe a billion dollar revenue company did this much more convoluted, complicated and highly atypical thing to save $250k and then just left it completely vulnerable to trivial replay attacks.
Could one or some of these things, plausibly, happen? Maybe. Taken together, though, it's a house of cards and every card is a joker.