Don't get your hopes up, since if it was me running an exchange I would most certainly refuse to assist you for numerous reasons (but the main would be the fact you did not have 2fa and exchange can simply blame you in this case to avoid any hassle).
Sorry for your loss. Hope you resolve this somehow.
It seems impossible that hacker can somehow intercept the emails. And this was part of the reason I thought my coins would be safe without 2FA. But the thing is, the hacker indeed found a way to do that. Almost all victims got hacked by resetting the password. This shows the hacker does not know the original password. There's is no other ip login history in my email account. Thus, the hacker has no access to my email account. Also, I never click the password reset link myself. Then the only explanation is that the hacker intercepts the emails sending by hitbtc.
hitbtc is using a third-party email service, which I think is https://mandrillapp.com/. My guess is that either the hacker hacked into the servers of this particular email service, or the hacker is an internal member of that email service. The worst possibility would be this is done by hitbtc's own employee.
So the hacker need to be able to read email to reset password. The hacker didn't just login with your password. However, they cannot withdraw. So hackers can access reset password email but cannot access withdraw email?