we are now fully patched for the openssl heartbleed bug.
all previous remembered login cookies have been invalidated,
so you will need to relogin to access your old account.
http://filippo.io/Heartbleed/#dicenow.com
I hope you're aware that heartbleed bug enables the attacker to reveal several (some - possibly all) user passwords.
ALL PASSWORDS SHOULD BE CHANGED.
It seems that the attacker somehow revealed passwords for at least two accounts. But you cannot be sure - if he revealed more than these two passwords.
But your site has the another flaw - so called sql-injection flaw.
P.S.: I happen to protect some https enabled servers and I patched the SSL LOGN TIME AGO. We had several sql-injection attacks, none successful, but even so...
You should find a professional help, security wise.