Anti-ATO should not clear out security keys that have been registered for a long time. If suspicious new keys were added, it should clear those.
From the audit log in my email no new keys were added before this was tripped.
I am not using a VPN and as far as I know I am not doing anything unusual. I might be committing the crime of having a Linux Firefox user agent but I somewhat doubt that was the problem, that's not that unusual.