It seems I found Dryja’s scheme is actually sound if you come up with a reasonable definition of oracle security which matches your claim.
I later found though there’s a bunch issues if you try and combine events from the some oracle (treat the some of anticipated signatures as a conjunction of the two outcomes).