You're overlooking
Mixin Messenger, which comes with an integrated crypto wallet and supposedly has over million users. Like I mentioned earlier, we don't have confirmation that the Mixin Safe service is part of the hack.
Correct me if i am wrong. Mixin Safe is actually a
Wallet, a sort of MultiSig wallet where you need two keys to spend the funds and one of the key is stored with the Mixin team themselves and it is time locked.
My concern is that It was not an exchange where funds are sorted and hacker access them, It is only a wallet and it was decentralized too (private keys with the users only) (don't know if it was open or closed source), so this means that hacker managed to get all the private keys? In theory, that is impossible