What I read is they hacked wallets that had the 'Milk Sad' vulnerability (predictable private key), but I'm skeptical as that's an old CVE, IMHO it's more likely an infrastructure or communications hack or a wrench attack - the suspect is now 'missing'.