“With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform. One GET request per user.”

Sequential IDs and no rate limiting is the first bug anyone checks for. The researcher reported it six months ago and got nothing back. The vulnerability is still live for 700,000 people who thought they were signing up to pray. Whoever built this took the contract and stopped answering email.