There is a detailed postmortem in the linked ticket explaining exactly how this happened.
This is the same phishing attack that hit junon yesterday.
https://news.ycombinator.com/item?id=45169657