Currently looks like the attacker had legitimate access to the required keys, so perhaps more of a traditional compromise rather than a cryptocurrency/contract centric one.
https://twitter.com/mudit__gupta/status/1425150994778787841?...
https://blocksecteam.medium.com/the-initial-analysis-of-the-...