the bit that stood out is the jump from a distinguisher to key recovery, because that only goes through once the distinguisher is strong enough and high-rate cube distinguishers tend to get noisy fast. so the paper closes the weight-2 case, but it still sounds like the real boundary is whether the public code leaks enough structure for the distinguisher to be reliable, not just the mask weight.