That's a hefty judgment. If we look at major attacks on TLS endpoints I'd summarize them as, in order,:
1. Memory safety
2. Weak / old configurations
3. Invalid state machine transitions
Rustls addresses all 3 of those, or at least it attempts to. (1) is obvious - it's rust. (2) rustls only supports the subset of TLS versions that are considered safe. (3) rustls avoids issues like gotofail and smacktls by encoding state machines as types, turning invalid state transitions into type failures.
Plus, the actual crypto primitives are extremely well tested and built off of other existing libraries.
So yeah, maybe some aspect of the crypto is incorrect, but, while interesting from an academic perspective, the real world ranks those other 3 things as way more important.