Perhaps something to do with the API (which is disabled by default but some victims have noticed was enabled) https://coinbase.com/docs/api/authentication
"If someone obtains your api_key or an access_token with the send or all permission, they will be able to send all the bitcoin out of your account."