> People who did not have this setting enabled or do not have a phone number associated with their account were not exposed by this vulnerability.
This is a bit disingenuous, given that you can't really open an account unless you provide a phone number to "verify" it.
Edit for clarification:
As gojomo said below (https://news.ycombinator.com/item?id=22233612) you may not need to provide it during sign-up, but your new account is almost immediately locked for "suspicious activity" and you need to provide a phone to unlock.