Was i Exposed?

Hello everyone,

As im getting started with Home assistant running on a Raspberry Pi. I discovered that I had 2 tokens which addresses I couldn’t verifiy. When I first setup HA I directly activated the 2 steps login with authenticator. I also started remote acces thru de nabu casa home assistant cloud.

But my question is actually was I exposed (hacked) or was it a token from an integration or something.
Can anyone log in bypassing the authenticator app?

As I was afraid of being hacked I reinstalled home assistant now.
Could anyone help me with these questions?