We have to stop comparing PQ schemes to elliptic curve ones. IMO ECC is a detour in history, its properties are incredibly good because it’s not quantum secure. Isogenies are good but don’t get close to dlog based ecdsa/bls/groth16.
I imagine the PQ paradigm will be multiple schemes that are good at different things. Instead of having a single scheme that is great in all dimensions we’ll need more schemes to build things and more engineering effort/complexity.
I just don’t buy linear proving and constant communication+verification complexity. It’s simply too good. Happy to be proven wrong though.