The collision attack step isn't targeted, but once you've generated more than the birthday bound of keypairs, the probability of a collision increases.
Given that there are approximately 2^252 valid Curve25519 public keys, there will most likely be 1 other valid Curve25519 keypair that produces the same exact 128-bit hash output (given the algorithm of SHA-256).
But once you find one of these, you can attack the fingerprints for those users.