ECDSA strikes again. Bad nonce generation (here: generating a 521 bit nonce by calculating a 512 bit number and then taking that modulo 2^521, which means the top bits of the nonce are always zero) leading to private key compromise. Classic.
Yes, although this is the rare ECDSA private key recovery issue where deterministic nonce generation was the cause of rather than the solution to the problem.