Check if it's accessed physically during the time when it's supposed to be off,
Is the computer Windows/Linux?
- For the former, check your "Event Viewer->Windows Logs->System" (wait for a few minutes to load) to check if it has a log with timestamp on March.
- For the latter, use journalctl --since "2024-02-20 00:00:00" to do the same as the above. (you can set the date closer to the incident)
If positive, then you can deduce that it's booted-up by someone who has access to the PC's hiding spot.
If not, the keys/wallet was leaked before that incident, e.g. wallet.dat file's passphrase was cracked in March but got hacked months before that.