From my observation, they didn't steal the coins,, almost everything went back to the imput address as change, they were just sending a message across to inform them of their coins being vulnerable and maybe seeking an offer to fix it the bug for them when contacted. They're good guys. It's something positive as PrivacyG noted.
The input address might belong to the hacker. It was funded by an address that received 3,996 BTC from a Liquid peg-out in this transaction
https://mempool.space/tx/8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140It only sent back 1,000 satoshis to the Liquid federation address along with the OP_RETURN message.
Here is more information, posted by the Liquid Network account on X.
https://x.com/Liquid_BTC/status/2096696272447218108