A smart contract vulnerability reportedly allowed funds to be drained from an mALGO staking contract without warning, leaving users unable to redeem their tokens despite official statements about on-chain redemption options.