What about prior discovery that occurred before all the other certificate authorities began to harden against theoretical attacks like this? MD5 based signatures and monotonically increasing certificate serial numbers used to be the rule, not the exception.
I have root certificates in my browser that are valid from 1998 to 2018. It's not so easy to verify that this attack didn't already happen 5 or even 10 years ago.
Personally I think it's extremely unlikely, especially since the chosen prefix collision attack they used has only been public for less than two years, but how could you know for sure?