>Nobody has been able to break the privacy in the 2 months that it has been live
because it's literally useless right now, wait till there's an incentive to break it. They have no security experts on the team, it's bound to fail in a big way if someone like uniswap adopts it, and WHEN someone breaks it, everyone will want off the ship
also there seems to be some global storage to store a contract's state, so all it would take is 1 node to get a job scheduled to it (not hard if there are a lot of transactions) and it would know about everything going on in the state, i.e. they can just read the whole order book