The breach stemmed from a vulnerability in transaction signing software that enabled the derivation of private keys from blockchain transaction data.