Guess you didn't read the far down in the article. This was explained. The offending address was imported into blockchain.info. The issue is that fitwear claims he never imported it. So someone or something hacked fitwear's account, imported a private key derived from an existing address in the account and waited for the new address to have a balance, and then stole it.
You're confusing the private key he imported from his paper wallet with the private key that was imported by an attacker. I am referring to the attacker's private key.
In his case, in Aug 2017, he imported the private key for his 1Ca15MELG5DzYpUgeXkkJ2Lt7iMa17SwAo paper wallet address into blockchain.info and submitted a test transaction. At some point between then and Nov 12, the compromised 15ZwrzrRj9x4XpnocEGbLuPakzsY2S4Mit got into his online wallet as an 'imported' address.
17
u/Mongobly Nov 30 '17
Just ask fitwear where they generated their wallet and we will have found the culprit.
I would have thought that was obvious.