The minting wasn't some unlimited backdoor they left open, this looks more like a bridge or multisig compromise where the attacker got signing authority, which is a totally different problem than the protocol having no supply cap.
A signing authority compromise that produces 4 billion new tokens still means the minting function had no on-chain guardrails, rate limits, supply ceiling checks, multi-block delay, that would have caught or slowed the issuance regardless of how the attacker got the keys.
Unlimited minting is the oldest red flag in the book, any yield I was chasing on Harmony just got printed into oblivion.
The minting wasn't some unlimited backdoor they left open, this looks more like a bridge or multisig compromise where the attacker got signing authority, which is a totally different problem than the protocol having no supply cap.
A signing authority compromise that produces 4 billion new tokens still means the minting function had no on-chain guardrails, rate limits, supply ceiling checks, multi-block delay, that would have caught or slowed the issuance regardless of how the attacker got the keys.