they stored a static login key generated by md5(strtolower($username).'::'.strtolower($password)); - so they could crack the md5 part easly and bypass the bcrypt encryption
thanks for the writeup, that was the hunch from skimming the article but good to get confirmation!
Slightly pedantic: "Discovery 1" email indicates that the $loginkey encryption was the weak md5 method until it was changed to bcrypt in a 2012-06-14 commit.
As a result, any accounts that were created before 2012-06-24 and that did not have their password changed after that date (which would generate a new bcrypted $loginkey) were vulnerable.