This post shows a thief managed to added himself to the victim's active key authorization at Steem. Then, he can transfer money from the victim's Steem account to his own Steem account.
The above screenshot shows the theif, jiganomics, is authored to the victim's active key.
The victim found his money was stolen, so he modified his password. Though the password of victim is changed, but the thief is still authorized for the active key, and the thief still can transfer victim's money to his own account.
At first, the victim doesn't know that the active key was authorized to the thief. After his friend told him that, he doesn't know how to remove the thief from the active key authorization. Even the victim is aware of the thief and changed the password, he still cannot stop the thief to steal more money from him.
The problems of Steem active key authorization:
When the owner of Steem changes the owner's password, the key authorization should be reset, or give the owner an option to reset. Then, the victim can stop the thief to steal money from his account by just changing the owner's password.
By implementing the above suggestion, the victim of the hacking can remove the active key authorization by simply change the password.
For current implementation, even if the victim changed the password, the thief still has the active key authorization and still can steal money from the victim's account.
To protect users, Steem/Steemit should implement the suggestion as soon as possible.