My completely unfounded tin foil hat at the moment is that ECC was pushed as a standard not because it was faster/ smaller, but the smaller bit size makes it less quantum resistant and is more prone to be broken first (if not already) via quantum supremacy.
You're right, that's pretty unfounded.
ECC is easier to implement right. Even the older ones that are full of footguns have orders of magnitude less footguns than RSA.
So don't fear them due to unfounded theories.