Why don't we use hybrid RSA and ECC then? Or hybrid AES and ChaCha20?
Software bugs is a weak argument for a new hybrid standard, and doesn't justify the additional complexity.
In his defense, ECC is unusually fast compared to both RSA and current PQ
In his defense, ECC is unusually fast compared to both RSA and current PQ