You're missing the attack in exactly the same way as the author does.
The same person doesn't distribute both of the files. Two different people distribute two different files. One of them is totally innocent and the party distributing that file doesn't even have to be in on it or have any relationship with the other person, but there is no way to tell which one it is.
The legal system is forced into either punishing and taking down the innocent file or not doing so for the infringing one. There is no other option when you can't distinguish between them.
But it isn't supposed to do that to the one which is just an ordinary use of a one-time pad by an innocent independent third party who has e.g. posted it in a public place for the intended recipient of the non-infringing message to receive it without there being a direct one-to-one communication between sender and the recipient. Or because there are multiple intended recipients and only those with the correct pad can read the original message so it's safe to publish widely.
The fact that some totally different person has come along and used your published file to encode an infringing one is not supposed to affect your legal status. But if nobody can tell which one is the original, the legal system has to choose between punishing the innocent and not punishing the guilty.
It isn't an algorithmic problem, it's an evidentiary problem. There are two different sets of bits and one is supposed to have a different "Colour" but the legal system has no information as to which one it is.
It's like someone discovering that the flashlight on certain phones is bright enough to blind surveillance cameras, and when someone points out that criminals could use this to prevent surveillance cameras from capturing their faces while they're committing their crimes, you respond that the legal system doesn't work like that because having an effective way to avoid being identified doesn't make your conduct legal. But that wasn't the original claim.