They should only use a computer that is air gapped to go online only when signing something. This is an op sec failure to not have this procedure
For that matter, I know signatures are long and human-unfriendly, but isn’t it on the order of a couple hundred bytes? Surely $1.5 billion buys transcribing the putative signature request into an isolated machine in a known state, validating/interpreting/displaying the request’s meaning on that offline machine, performing your signing there offline, copying down the result, and carrying the attestation to your secret conclave lair to combine with the others’ or whatever?
(No, I won't suggest carrying the BIOS chip around)
They were attacked when they went online