So on a scale of complete dumbass to blithering idiots, how badly did the SDC team fuck this up?
1. The bug itself was an error that any very amateur cryptographer could make (that would include me) if they were foolish enough to try to implement this without any sort of help or review from a competent cryptographer or mathematician (that would not include me). That still foolish, but perhaps understandable given limited resources and a mandate to implement the promised features anyway.
2. The "SDC Deanonymized? Nope" blog post was an epic and complete fail on the level of blithering idiots who are also complete dumbasses. That includes the claim of not being able to reproduce the flaw in 10 hours of trying. I'm not sure I believe they even tried, or which would be worse.