you got the idea. i was thinking about the possibility that the mines spend the coins from the hackers address to a bitfinex address. they usually write transactions from a to b. so i thought they could also write a transaction where they force the attacker to send it back. i figuerd it would work fine if the majority was for it and i did not saw my mistake. I think i do now.
the miners do not have the private key of the hackers address to sign it. so this whole idea of mine would not result in a valid block. Am i right?
theoretically it would be a fork with consensus .
i assume something like this situation needs to happen: https://bitcointalksearch.org/topic/m.9531 (not to be mistaken with what OP is asking, this was a bug but practically they invalidated the block 74638 hence the transactions that exploited the bug in 2010)