I spent about 30 min looking at the (old) code and could find nothing obvious at first sight, they might have removed some check in the POS Code and got a malicious client sending those large blocks. I'm just not sure why they added two blocks recently since the market is already frozen..