Could one single person really inflict that much damage without a balance/check or code deployment review process in place?
I'm still leaning heavily towards an "oopsie" with routing that accomplished the same thing, however.
I am talking in a very generalized sense, not for this particular issue. But I don't think the code review/deployment process is entirely safe against internal bad actors.
The whole point is to write C that appears on the level at first, but actually has a subtle exploitable flaw. The flaw is supposed to appear like a simple mistake for plausible deniability. Some of the winning responses are very devious.