Once a user has completed the redemption process by burning their tokens via a burnlisted address, the address remains on the burnlist and it's possible to send unlimited tokens to that address - even if not associated with the redemption. So these tokens will be unrecoverable.
Easy solution would be for the Controllers to blacklist the address as part of the redemption closure procedure.
The address label also still says "Frozen for redemption" so could probably say "Burn address - do not send tokens here" upon completing standard redemption process.
Once a user has completed the redemption process by burning their tokens via a burnlisted address, the address remains on the burnlist and it's possible to send unlimited tokens to that address - even if not associated with the redemption. So these tokens will be unrecoverable.
Easy solution would be for the Controllers to blacklist the address as part of the redemption closure procedure.
The address label also still says "Frozen for redemption" so could probably say "Burn address - do not send tokens here" upon completing standard redemption process.