They left people's wallets with "aliases" open to be cracked by anybody who found them for years, messed up their RNG and revealed some users private keys, a few XSS mishaps, and their support reset 2FA keys for hackers with social engineering.
These sound like mistakes that many beginner companies can easily make when trying to craft them. Why is there a demand for perfection out of the gate? And why are offers to remedy the situation not given the same kudos?
Because it only takes one flaw for money to be permanently lost.