Clearly you do not understand how time consuming it is to crack a encrypted password. If they do not know the hashes or the salts, it's gonna be extremely time consuming to crack a for example password with 12 length mixed with chars and digits. Since a shitton of people have gotten their accounts compromised, I'm 110% this is not some lone hacker brute forcing passwords.. Most likely some фекал money hungry server like for example Feenix sold off their database, hashes, salts everything to someone willing to pay enough. What they got is a bunch of accounts that people probably use the same username and password on 4 other projects and now their accounts are obviously compromised.
What did the token website say when you generated your tokens? "Change password! Use unique password etc.". Creating new account? "Use unique password!". Elysium have done what they can and warned people but if they do not wanna follow advice the burden is on them. Sorry to say but the fault lies entirely in the users not putting thoughts in their account security. Let it be a lesson learned, it sucks but it's not Elysiums fault you use same password on all your personal accounts.