To summarize
1. There are two groups of people here. One is people who invested in the white contract (through white list, because they were selected from the community, or because the got the ICO address from someone else). Second group is people who got scammed (because they trusted the Slackbot and send on the wrong address or because they have used wrong address provided by hacker on the hacked webiste, without even checking if it is contract address and not wallet address).
2. Yes, devs had poor security of both Slack and website. But scammed people didn't even check when they are sending the funds.
3. Devs decided to be kind enough to send free tokens even to those people who were vistims of the scams (I understand only the website scam, not the Slack scam, but who knows). Also the people who sent the ETH to the right address might have an option to send their tokens back and get refunded (probably only some people will use this possibility, the rest will not).
Situation is really simple. This mess could be fixed in matter of hours. Scammed people would be grateful that despite they deserved nothing for their mistake of not checking where they are sengidn, they would be sending token anyway. And white list people who sent the coins to the right address would feel secure that if they want they can keep the coins or return them (preferably for a limited time). Devs can either destroy those coins or issue another round of sale, whichever they prefer. Everyone is happy, confidence in project rises. Of course some trolls are trying to make a chaos here. And devs for unknown reason are not communicating with the community instead of simply implement the above solution, which is the only fair and natural solution here. Let's hope they will fix this ASAP and we can move on to actual development of the project.