He also noted:
@Alex Khomenko told me in another place, that there may be
a secondary authentication on password changes from the
forgotten password link, in the US PayPal. If true and
currently in place this would mean that the US is not
vulnerable, although they may still have the email bug
He said he doesn't use PayPal himself and that he only requested a change password link when he was trying to contact them about "effective spam". Perhaps he supplied them with one of his email addresses and it happened to have a counterpart at a different subdomain (like example@email.com vs example@email.com.au)?EDIT: Formatting.