Huh. I guess whatever algorithm comes next is resistant to half of the secret being compromised, then.
Edit: It looks like they concatenate things from the two algorithms a few times in the process, so maybe they figure it would be difficult to isolate a vulnerability assuming either one is strong.