Seeing open-source project code, he assumed the project was safe, ignoring smart-contract vulnerabilities. The team had built backdoors and quietly stole user assets.