The proof of security for XSalsa20 applies, without modification, to
'XChaCha20'. (It, in fact, applies equally well to X-AES, but the security
strength for that is quite poor because of AES's blocksize.)

One can derive a similar result in the indifferentiabity framework, as
well. (It follow straightforwardly from Coron et al.'s Chop-MD result.)

