After a lengthy conversation with MagicTux, unless it does turn up that mtgox has been hacked, neither of us can figure out what happened. Its obviously not me and I didn't fall for a phishing expedition, and Im pretty sure its not on his end. His description of security on the new post-hack mtgox is pretty decent. Its not perfect, but he has gone to great lengths to prevent a repeat.
Even if they dumped the password database, the passwords are sufficiently salted and hashed that it is extremely unlikely they grabbed my password first.
I also do not think it is likely the recent DigiNotar or Globalsign break ins have produced SSL certs to attack mtgox with (which WOULD explain this) because mtgox uses EV certs and as far as I know none of the fake certs were for EV, but DigiNotar and Globalsign both DO issue EV certs. Although I am not ruling this out.
DigiNotar knew about the break in for months, and I obviously have logged in since then.
Tux has replaced the missing BTC.
Asking once again. Do you use a Yubikey on Mt.Gox?
As Ive said in the past, I do not believe that they improve security.
You are much smarter than "15,000 customers and over a million users in 90 countries" (from the Yubico homepage), becuase you know that a two-factor authentication is just bull shit. Banks use it just for fun. Or maybe you don't know what you are talking about.