I still don't entirely get what has happened. So he runs a bitcoin node on a compromised machine. But why would he store (or use) his 200+ BTC private keys there? He also mentions:
After reading some of the (many many) replies to tweets, it seems the story is pretty much what I summed it up as: he got compromised and failed security 101
They likely used the access they had to further infect or snaffle credentials etc - a very simple and obvious one is reverse SSH tunnels for example
> No, they got my cold wallet too somehow
How can that happen?