I'm 100% positive that many targets have had their keys extracted, but it's hard-to-impossible for the attacker to choose what fragment of memory the server returns, and it depends heavily on the server in question. What works against nginx won't work against lighttpd or apache.
I hit a site I control repeatedly yesterday and couldn't even get any common byte-arrays in common across hundreds of connections.
Of course, as good practice, all organizations should treat their keys as compromised and issue new ones.
Also, his "it leaves no trace" is a problem. It's trivial to recognize the traffic pattern.