I think the bigger picture is that online security is an endless thrust-and-parry business, with serious consequences. It's not one OS versus another; they are all under assault to some degree, from well organized and financed criminal/state entities. Weaknesses are systematically found, hoarded/sold, and exploited for financial (or sometimes political) gain. XP is/was a venerable OS, but it was not designed for this new reality. It's not fearmongering to anticipate some waves of nastiness following the end of support.

In practical terms, I'm wondering about the number of small-store outfits using point-of-sale equipment that may (?) be vulnerable. I might just take the approach I already use with all other online purchases -- a credit card with a $500 limit for everyday stuff. That controls my vulnerability (and the credit card issuer's) to a manageable number without a huge loss of convenience on my part.