@mawhrin this is a difference between the centralized case of Facebook (etc) and decentralized social networks. In a centralized situation, people report the malicious change, and the history makes it esy to verify that yep it's malicious, and it gets taken down quickly. And they're doing automated moderation, so in the really egregious cases like putting the kind of violent images that give people nightmares in people's faces, it's likely to get taken down before anybody even sees it.
In fedi, there generally isn't any automated moderation, so the images are going to propagate. And if the post is from a self-hosted instance, or an instance with malicious admin, then the reporting and takedowns have to happen on an instance-by-instance basis -- which not only exposes thousands of moderators to the grisly (or racist, or anti-rans, or whatever) stuff, but also means that it's going to be up on most instances for a while because volunteer moderators don't always respond instantly.
Even in cases where it's only disinfo, it's not really clear how much the history helps (other than allowing reporters and moderators to verify that it's changed). Most people don't check the history of posts, so if they see something that somebody they follow has boosted -- or has been widely-enough boosted to get into the trending lists -- they're likely to believe it. So I really do see it as likely to get exploited at some point.