TLS certificate was used only to access the website, the only way to abuse it is to perform a complicated and personalized MiTM attack. It can not be used to decrypt any of past web sessions due to Diffie-Hellman keys and is in no way related with VPN traffic.
We will release a public comment today to explain what happened, however, there are no signs indicating that any of our user data have been at risk.