http://34reqsy6tqou6avwrkm23s4mpkrwz3drtq2e5yr7sywi76h7plnaahad.onion/articles/xmpp.xhtml
If the attacker substituted a fake device, they could just as well insert a fake message ( The fingerprint XX XX XX that has just appeared to you is totally real, bro ), and pretend the shown key is real. Of course - again - your recipient needs to have an outside channel for this to matter in the first place.