> 4. An attacker obtained 5 of 9 keys, which is the signing threshold.
How?
How?
> The attacker managed to get control over Sky Mavis’s four Ronin Validators and a third-party validator run by Axie DAO.
Easiest explanation: at least one Sky Mavis employee and one Axie Infinity employee who have access to those private keys got together and took all the funds. Perhaps it was only one employee; it's not clear to me what the difference between Axie Infinity and Sky Mavis is (there isn't actually an Axie DAO, there's just a web page where they say they plan to be a DAO in 2023).
Easier explanation: they were all in a Dropbox or something stupid like that.