Vulnerability through honesty ?
Is it possible that this blackhat exploited the vulnerability purely BECAUSE of 'Full Disclosure' of bugs and having access to the entire source code ? Imagine the sequence of events:
1. A developer/reviewer flags a vulnerability on a public forum.
2. The support team say "Yep, good call. We're on it."
3. Blackhat reads forum and says "Yep, good call. Thanks for being a thousand pairs of eyes to my one pair.", and off he goes to work out ways to use this knowledge in creating an exploit.
4. The support team say "Yep, we've fixed it good. Download the latest version, and you'll be safe."
5. Not everyone using the software knows about either the vuln or the fix. They happily go about their business.
6. Mr Blackhat P\/\/n5 the crap out of them.
7. ???
8. Profit !
cf. 'Security through obscurity'. Also, check out 'The Morris Worm'.