They answer this point on the website: "Q: Why do you use SHA-1 in the place of a MAC? [...] since this means still requiring at least 2^128 operations (instead of 2^256 with, say, SHA-2) to even begin trying to break this scheme, the trade-off seems fair."
Why not break the crypto (and take the money) if it's so amateurish?