What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO DocHex pretending to be someone else.
(It's Coinkite (nprofile…j342)'s CTO who made this error, not a junior C developer.
It was the senior CTO pretending to be a junior while he talked to himself in issues and PRs.)
All of the following can be verified:
