CSRF is a fake...In my opinion...
I think in that way exchange covers their own impotance to prevent attacks...
I didn`t use any site at 16-40 14/06/2011 during hard DDoS attack, but my 13.4 BTC were successfully stolen...
So Mark says the same things everytime: "transaction was made from your account with the correct login/password, we are not responce for this"
Of course with correct!!!
How It could be with incorrect?
:facepalm: