It was obvious that this wasn’t white hackers, even though some guys here were hoping the situation wasn’t negative. I believe that white hackers would never sign a transaction in op_return, since such a large transaction would be noticed by on‑chain analysts anyway. And white hackers always end up sharing information about their victories over hackers on social media. In our case, this signature was a naive attempt to dispel suspicion.
I am curious why you consider it was obvious they have malicious intents.
Do you consider it a positive out come now that a significant part of it was sent back? I would personally say this is one of the best out comes possible. 600 Bitcoin is still a GIGANTIC loss, but getting a quarter Billion Dollars and leaving around 45 to 50 Million to the hacker is still some thing.
It was simply about time until some body else would have found the same vulnerabilities and did a Coldcard type of attack where every Satoshi is irreversibly pulled in to their own pockets. A very big pay out, a pretty asshole kind of pay out even but it could have been a lot worse.