Earlier quoted context omitted.
> You're a criminal with a one-in-a-million opportunity. Wouldn't you invest an extra week pushing a more fledged out exploit? Because the way this was pulled off, it was going to be found out right away. It wasn't a subtle insertion, it was a complete account take over. The attacker had only hours before discovery - so the logical thing to do is a hit and run. They asked what is the most money that can be extracted…
"found out right away"... by people with time to review security bulletins. There's loads of places I could see this slipping through the cracks for months.
It might get missed, but I sure notice any time account emails come through even if it's not saying "your password was reset."