Something similar happened to me too. Someone got into my email and did a password reset request on Cryptsy. They were then able to log into my account, sell my alt-coins, and withdraw almost ALL my coins (the only coins they saved were the ones where its exchange pair was no longer active)!
And after communicating with Cryptsy, I found that all this happened from a never-before-seen IP and was withdrawn to never-before-seen BTC and LTC addresses. I lost over $20k worth of coins total.
Why cant Cryptsy just freeze withdraws after a password reset is requested (especially if the reset comes from a different IP)?
BTC-e.com does it all the time. They put a withdraw hold for 48 hours every time your password is changed, no exceptions. And the 48 hr. gives people enough time, so even if theyre on the road or traveling, they still have enough time to get to a computer and check their account before any damage can be done.
I understand the argument that, well, its my fault for putting money on the exchange. You shouldnt send money if you cant afford to lose it. But if thats the case, then the solution is to stop putting money on Cryptsy. Just think, if everyone did that, then there would be no trade volume and therefore nothing to support Cryptsy.
I started trading on Cryptsy the first day they opened, and I even own some of their stock, so I want to see them thrive. But I dont see that happening if they cant reasonably keep their customers coins safe.
If people cant put their coins on there to trade, then people will eventually take their coins off of Cryptsy (just like theyre doing with Mtgox) and Cryptsy will be no more.
Ill be making a video about this issue (when I get over my embarrassment of the whole thing). But until then, theres my story.