"The attack breaks the pseudorandomness as it allows adversaries to evaluate the OPRF without further interactions with the server after some initial OPRF evaluations and some offline computations."
https://eprint.iacr.org/2021/706
https://github.com/isogenists/isogeny-OPRF