This is very nice work. For those who are interested in academic work about detecting/preventing such attacks, there have been some recent papers that looked at the formal verifying protocol models [1, 2] to (dis)prove the absence of such vulnerabilities.
1. https://eprint.iacr.org/2019/779 2. https://eprint.iacr.org/2020/823