Assuming that MtGox (let's say MtGox, not Mark) did indeed introduce transaction malleability as a feature, that should be very easy to prove with source control commit logs. But if the malleability vulnerability was already there to begin with, it would be very hard to prove indeed that MtGox was taking advantage of it.
Edit: I should also add that Mark in particular has not proven himself smart enough in my eyes to pull something like this off. In terms of technical skill, yes, but this requires a very human approach to deception which I, based on the conversations I've seen him have, do not think he possesses.