I'm glad some people are posting on this thread, but frankly I was expecting this to get a lot more attention. This would be the first story, ever, of a person losing money who had a Yubikey and did not also have a trading API key floating out to be used. I've never used a trading bot, so I don't know if there was a mistake in granting permissions there... but this would be a Bitcoin first.
Well it is the weekend so it is understandable. Although having $4,000 stolen hurts, there is not much more I can do about it. I'm confident there is no mistake in granting permissions as you would have to consciously check the 'withdraw' box to grant withdraw permission. I also combed through the trading bot source code at one point looking to see if there are any malicious code.