Open sourcing code is one thing. Open sourcing the email addresses of vulnerable victims is something else. Itβs like publishing the largest vulnerability of all time before it can be patched
All the email addresses are pulled from public leaks, often from years old leaks. Nothing like your analogy, if you're still vulnerable you should consider yourself lucky you haven't already been hacked.