An enterprising blockchain-spelunker
might be able to put a very rough ballpark estimate on amounts lost by any affected repeat-payers, by:
(1) Find all confirmed transactions that have a signature that appears in non-canonical form (and thus likely confirmed under an unexpected TXID);
(2) For those transactions, identify the paid-to addresses and amounts: possible targets of make-up transactions. (Of course, it may be hard to distinguish true targets from 'change'.)
(3) Find later transactions with the exact same paid-to addresses and amount: these may be erroneously-issued repeat payouts.
Of course, if the complaining user offers a different address for the make-up transaction, this wouldn't work. On the other hand, a researcher already working hard to correlate affiliated addresses, now or in the future, still might be able to surmise when duplicate-amounts went to affiliated-addresses in succession during the active exploitation period.