The only output check of nonce_gen_counter uses nonrepeating_cnt = 0, so the following mutant replacing secp256k1_write_be64 with secp256k1_write_be32 (which could enable nonce reuse) survived because zero serializes the same either way.
diff --git a/src/modules/musig/session_impl.h b/src/modules/musig/session_impl.h
index d8a3cca..710c4c5 100644
--- a/src/modules/musig/session_impl.h
+++ b/src/modules/musig/session_impl.h
@@ -447,7 +447,7 @@ int secp256k1_musig_nonce_gen_counter(const secp256k1_context* ctx, secp256k1_mu
memset(secnonce, 0, sizeof(*secnonce));
ARG_CHECK(keypair != NULL);
- secp256k1_write_be64(buf, nonrepeating_cnt);
+ secp256k1_write_be32(buf, nonrepeating_cnt);
/* keypair_sec and keypair_pub do not fail if the arguments are not NULL */
ret = secp256k1_keypair_sec(ctx, seckey, keypair);
VERIFY_CHECK(ret);
This add a new test, which checks that for random 64-bit counters, nonce_gen_counter gives the same nonce as nonce_gen.