Great post. Highly recommended. Thank you for sharing it on HN.
My take: Many "Web3" applications naively rely on conventional "Web2" infrastructure, so they are exposed to conventional attack vectors.
The OP is just the latest example of this.
Here's an earlier example showing how easy it is to mess up a Web3 app if it naively relies on Web2 infrastructure:
https://moxie.org/2022/01/07/web3-first-impressions.html
The author of that earlier example is none other than Moxie Marlinspike, creator of Signal.