It seems that they are been held as hostage by those hackers claiming to be a whitehat.
Labeling them as whitehats is not suitable, as we know most whitehats will report these and take any reward outside of the fund he was transferred. Those BTC being transfer and hold always for leverage.
If they don't have any bad intention, then why it seems that they are forcing the company to pay them from the hacking incident happened and also for exposing those exploits?
They know that with this size of funds, it's gonna attract everyone (blockchain team, chainlist transaction analysts, every blockchain service, hard to mix the fund with these size). Decide to pretend like good guys with whitehats claims, he knows if he reported these claims and took a bounty not from these funds but from the bounty allocation (as example). His reward could be under 0.1%-0.2% of the potential losses 4,000 BTC, and if scared not to be paid, he can somehow make these using escrow with the Blockstream team.
Curious to know on where this case ends up. It seems the hacker is eager to get their rewards and will do lots of crazy things to convince the affected platform to give what they want.
They will try their best to get as much bitcoin as much they can take. 598 BTC can still give Liquid Network a massive potential deficit, debt, and undercolateral for L-BTC. Surely other alternatives will try to raise some funds, just like @FinneysTrueVision shared for the KelpDAO case. They do DeFi United (some of DeFi project, help KelpDAO for the deficit and debts) due to the exploited.