I worked on the OTF-funded security audit of Cryptocat. (The report: https://leastauthority.com/static/publications/LeastAuthorit...) While I wasn't involved in arranging the work, my vague memory is that a publically-disclosed audit was a condition of the funding -- I think the OTF had that policy in general. (It's been a few years, and I haven't kept up.)
Even the author of CryptoCat now thinks you should not use CryptoCat, but I would not rush to assume ill of the OTF funding it back then.