Yes, you still need to be careful, especially if you have reason to think that the proof was from a malicious actor.
https://leodemoura.github.io/blog/2026-8-1-postmortem-for-ke...
(N.B. from August 2026)