The Harmony Bridge was secured by a 2-of-5 multisig, of which the following addresses were compromised:
- 0xf845A7ee8477AD1FB4446651E548901a2635A915
- 0x812d8622C6F3c45959439e7ede3C580dA06f8f25
The attack vector which allowed the hacker to take control of these addresses remains unknown, though some have suggested that they were hot wallets with private keys kept in plaintext.
If an attacker managed to gain access to the servers running these hot wallets, they would have access to the two addresses necessary to pass any transactions they like, such as draining $100M from the bridge.