I suspect it won't help. If your key is compromised, the previous sessions are compromised as well. I.e. the attacker now knows the password.
There is no indication or mention that key exchange was compromised. SSH has forward secrecy, so compromising the authentication keys does not compromise the encryption keys.
Are people using password only at risk?
Not at this risk, but possibly others. Requiring both is always better.