Details
After further investigation with @danfinlay and team, it appears that the compromise was due to a registrar that has locked up the email domain.
It appears to have only affected this one account.
Some more details in thread about what we're doing next.
Earlier this morning @danfinlay's account posted a message about a token. This message wasn't posted by Dan and we've been looking into what may have happened.
We're still investigating and don't have a root cause yet, but believe this issue only affects this particular account. More details in thread.