"If pipefail is enabled, the pipeline’s return status is the value of the last (rightmost) command to exit with a non-zero status, or zero if all commands exit successfully"
The proposed scheme seems overly complex and I don't immediately see any advantage over explicitly invalidating all issued (randomly generated) tokens after the password has been reset.
Why was the incredibly important caveat -- this vulnerability only affects configurations which are using netmask-based permissions -- left to the last paragraph?