Researchers from INRIA, MSR, and IMDEA discovered the FREAK vulnerability in TLS/SSL implementations, including OpenSSL and Apple clients, which exploits weak export-grade 512-bit RSA encryption to enable man-in-the-middle attacks. The flaw stems from legacy U.S. export restrictions on cryptography that were never removed from implementations despite the policy ending decades ago. The discovery demonstrates the value of formal verification methods and systematic testing in identifying security weaknesses in complex cryptographic protocols.