https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu...
To make things even worse than rolling their own hash function, they're claiming the flaw was intentional! This makes them hostile and untrustworthy to the open source community if this is true and further erodes confidence they know what they're doing if this is their attempt at PR spin:
https://hackernoon.com/why-i-find-iota-deeply-alarming-934f1...
> Next, and in my mind most damningly, Sergey Ivancheglo, Iota’s cofounder, claims that the flaws in the Curl hash function were in fact deliberate; that they were inserted as ‘copy protection’, to prevent copycat projects, and to allow the Iota team to compromise those projects if they sprang up.