So I wonder if some things using the same chip/library are not actually vulnerable because they blinded the operation?
It's *better* to use a constant time algorithm, but that's harder to do in a curve generic way and has a pretty significant performance impact (particular before the safegcd paper).