This is pretty nifty. Obviously there's a lot of malicious uses for this, but as someone who supports a lot of seniors with near inability to remember passwords, this sort of thing has a practical use.
Its true that the first failure can be used to mitigate some of the visible harm of the second, but any place that features a coincidence of the two failures really should be taken as a particularly strong sign that, in that place, passwords of the type used are entirely the wrong tool for the job.
Still ongoing research in terms of impersonation and other attacks, but quite interesting.