What am I missing here? An active attacker will just terminate the connection on both ends. There will be 2 authenticated session IDs at L3. At L7, how will an application authenticate the L3 ID in such a way as to discover a MITM? Even if it can, there needs to be a new ioctl (or similar) for the application to learn the L3 ID. That's rough for the large legacy of applications that might otherwise benefit from this.
I'm sure I'm missing it, since this has been 10 years in the making, authored by well known folks. The referenced USENIX paper discusses how both ends of the tcpcrypt connection can know there's no MITM. However, in the case of intercept, the other end of the connection is the MITM.
Because tcpcrypt uses ephemeral public keys, there's no L7 identity proof, such as is offered by TLS (as far as it can). This further permits MITM.
An active attacker can also just strip the TCP-ENO bits from the SYN. If [just] one side insists, the attacker can strip it just from the other side, for performance.