They'd have accepted the risk for this to come up via external review and vulnerability reports before they could harvest a substantial amount. This would have destroyed the companies reputation similar to what we see now. There's also a the risk for an attacker to grab the funds before they get to collect them. Both scenarios seem way more likely then CoinKite or an employee sitting and waiting for five years — especially as there where multiple reports of individual incidents over these years, each asking for further investigation.
I totally get why people are upset and wouldn't rule this out entirely, yet it seems far more unlikely to me. The more likely scenario imho is that they were too arrogant to look into the reports, giving the attacker the time to proceed slow and steady. Then, last week the attacker might have lost exclusivity on the insight and someone else joined the drain, forcing one of the hackers to go full blown.
quotingCrazy tweet.
nevent1q…et0p
![]()
