Isn't that what hardware wallets are for? And this would imply they are using some centralized service for their multisig setup since it affected al cosigners. I am sure this is an advanced attack but I have a hard time believing this was a real multisig setup.