That a key exist on a random keyserver means nothing. There is a spec that explicitely says "if you want to use my key here it is" and Proton doesn't respect it. what does it mean that you found the key on some third-party domain ? There are 0 safeguards, I don't know what they're going to do with it, there is no obligation from any side. A key in keys.openpgp.org means nothing.