To me there's even more uncertainties:
So, is Bitcoin address
15npoeYGso1qyFAo7Wzw35s4fXMDh5ryrj confirmed or not (not really relevant to crack the password)?
I have issues with the "clarity" of remembered fragments of the password:
- There were two words placed between the Xs.
- The two words they remember are ngn and ycm.
- They strongly believe that both words had the same length.
When you speak of "words", you mean lowercase strings of characters a--z, not words from some dictionary, between the "X"? It could be valid dictionary words, but it must not necessarily be dictionary words, correct?
Any further constraints regarding word length, minimum 3, maximum length?
If the lowercase strings are not of same length, by how much could they possibly differ?
How about the assumption, that both strings have to differ, i.e. must not be the same?
- The prefix was either !x or !z.
- The suffix was either !@#$% or (12345, depending on whether Shift was being held.
Can we assume an American PC keyboard layout? "!z" or "!x", "z" and "x" are in close proximity. I wonder if it also could be uppercase "Z" and "X", because for "!" you have to hold down the shift key.
Suffix
!@#$% (shift key held) or
12345 makes sense. You have also "open parenthesis" before the numbers. Why is that, can you clarify?
Your example makes only partly sense, because your suffix is truncated.

Should a truncated suffix be considered a valid partial fragment?
I'm trying to narrow ambiguity down to as little as possible because otherwise it blows up the search space or hampers potential cracking success.
And also, please disclose some important information shared in the Telegram Group like the other poster did.
Not all of us here use Telegram.
I don't like it, too, that possibly other valuable information is hidden behind some Telegram group. OP should present everything relevant here when they open a topic here.
At first, it doesn't look like a terrible cracking job, but considering that OP has presumably some years of experience, I wonder why this recovery still resisted cracking. Something's a bit off, I just don't know yet what.
It makes sense to me to attack this with some sort of rule and known fragments based attack via hashcat. Question to OP: has your or the used toolchain been verified that the encryption hash has been correctly extracted?
You state that you had no access to the encrypted LUKS partition. I assume the original owner still has access. Has the original owner verified that they know how to properly extract the encryption hash? (I would always verify my toolchain before I start a potentially lengthy and possibly costly recovery!)