Why do you think that these funds were stolen?
Why do you think is was because of a bug in 2FA in BTCPay server?
Why does it say "exposed macaroon" in your screenshot? More specofically, why is that supposedly what enabled the funds to move and what does it have to do with BTCPay?
Oh shit, they intentionally left the real vulnerability out of the release notes and changelog. That's seriously fucked up.
I stand corrected.
After reading that, I believe their blog post. There was more to tge update than the disclosed 2FA patch.