Okay, apologies, Raz, since when you first reported it (wish I'd seen it) you reported it as something that was happening and that you had no idea why.
I'll go through the source code again and see if there's a way for the system itself to plug the wrong user number into the reply URL.