We saw malicious activities by users where all the user's accounts were withdrawing rewards into a single bank account.
Being a small team and time-sensitive product we did not have the option to put bandwidth or stop the functionality.
Started talking to one of the scammers, and told her that I was one of them, she was curious about how we being other users found her contact. The answer was we hacked the DB and found out that she was also withdrawing coins from multiple profiles to a single account. Praised her and told her that it was very tough to break that thing. She was like “You guys are fools, it's not that tough. I am doing it like this”. We fixed the bug in the next 30 minutes. We told her that your method was not working for us. Maybe the company fixed something. 🥲