The exact leakage path has not been demonstrated yet, but it's clear it was a GG20 bug of the same form as a Paillier-modulus attack: a malicious participant can publish a malformed Paillier modulus during keygen, then use later signing/MtA rounds to extract honest parties’ ECDSA shares.
It's likely the latest GG20 patches protects against this, but my recommendation is for thorchain to migrate to DKLS with
@silencelabs_sl maintaining the lib.