Bruce Schneier already posit that hack-a-thing challenge is not a good test or proof of whether a thing is vulnerable. Back in the days when everyone was coming out with hash and cipher algo there were bounties offered as PR of how strong thingX was. Not everyone is going to take up a challenge, if I were a real criminal I would discover the vulnerability (if any) and keep it to myself because the exploit, especially a secret one, is worth more than the bounty, and has a longer pay period.