IIRC, it was a nonce-not-used-only-once vulnerability, wasn't it? Wouldn't that be tricky to detect, even in Rust?
Regardless, it's quite unfortunate to see Colin's nits picked in this manner, dredging up some mistake from almost 15 years ago (which he handled as responsibly as could be expected), given all of the work he's done on FreeBSD and for giving the world scrypt.