https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu...
To make things even worse than rolling their own hash function, they're claiming the flaw was intentional! This makes them hostile and untrustworthy to the open source community if this is true and further erodes confidence they know what they're doing if this is their attempt at PR spin:
https://hackernoon.com/why-i-find-iota-deeply-alarming-934f1...
> Next, and in my mind most damningly, Sergey Ivancheglo, Iota’s cofounder, claims that the flaws in the Curl hash function were in fact deliberate; that they were inserted as ‘copy protection’, to prevent copycat projects, and to allow the Iota team to compromise those projects if they sprang up.
The creator requested an open, live debate to put these claims to rest. They haven't accepted and probably won't.