2.5 million requests over the course of a day is a drop in the bucket for a large scale enterprise site. Sure, you would expect to see reasonable protections in place, but without some sort of prior knowledge (or dumb luck) it would be extremely difficult to find this bug (hence the two year window)...
-----
Angels and ministers of grace defend us! -- Willie S.