So many issues with IOTA
claiming to be open source when you have closed source centralized control via coordinator that decides which transactions are real, changing hash functions for "copy protection" to hurt others trying to review code for security or replicate - completely unprofessional
https://hacked.com/iota-update-tangled-web-home-rolled-cryptography/
There is still no evidence that the mistake was added on purpose.
RE: IOTA's "Vulnerability"