They appear to have authorized a malicious DApp to transfer their tokens, leading the assets to be drained immediately.