@WhiteHatMage@lonelysloth_sec Nope, they closed theirs as invalid. That was the annoying part. They haven't fixed the vulnerability since they don't want to pay a bounty to either researcher. They would be praying that no bad actor is watching when they move the funds from the contract to freeze it midway.
@lonelysloth_sec@WhiteHatMage Something similar happened to me. Someone had submitted the same permanent freeze vulnerability with about $10m at risk without a freaking PoC. They just did a leisurely, semi-illiterate report. When I submitted mine, it was marked as a duplicate. $150,000 gone down the drain.