Not just that, a couple of other bad decisions that caused made many websites inherently insecure https://sakurity.com/oauth
However, all server-side attack scenarios listed there are not possible with Hydra. Some of them also boil down to misusing OAuth2 for authentication, which is why we have OpenID Connect.