Alright I'm convinced THIS IS NOT A DRILL.
It is a small minority of users, not everyone.
We DON'T KNOW what the attack is. Could be RNG, could be NONCE, could be something else. We DON'T KNOW if it affects only single sig with no passphrase, or if it's a different layer. Use multisig, preferably multi-vendor.