Author here: the interesting/scary takeaway from this is that existing Python packaging tooling makes it very easy to miss-tag a binary wheel. Mis-tagged wheels are in turn trusted without any ABI checks, meaning that a wheel can be marked as compatible with a Python version when it’ll really crash the interpreter (or silently do something wrong, like corrupt memory).
In our search, we found that roughly 15% of all packages with ABI3-tagged wheels contain at least one mis-tagged wheel. That includes packages with millions of downloads, suggesting that crashes due to ABI mismatches are lurking in a large part of the Python package ecosystem.