Analysts traced the flaw to a privileged minting role controlled by a single externally owned account with no mint limits or oracle checks.