> The attacker used hacked private keys in order to forge fake withdrawals.
> The attacker managed to get control over Sky Mavis’s four Ronin Validators and a third-party validator run by Axie DAO.
Easiest explanation: at least one Sky Mavis employee and one Axie Infinity employee who have access to those private keys got together and took all the funds. Perhaps it was only one employee; it's not clear to me what the difference between Axie Infinity and Sky Mavis is (there isn't actually an Axie DAO, there's just a web page where they say they plan to be a DAO in 2023).