Some things were not plainly spelled out:
* July 11 2023 this was caught, April 2021 it was suspected to have happened. So, 2+ years they had this credential, and 2 months from detection until disclosure.
* How many tokens were forged, how much did they access? I'm assuming bad if they didn't disclose.
* No timetable from once detected to fix implemented. Just "this issue has been corrected". Hope they implemented that quickly...
* They've fixed 4 direct problems, but obviously there's some systemic issues. What are they doing about those?