Hey there! Nice to meet you!
Since you mentioned that you are still signed in to your Xbox account, please try going to account.microsoft.com > go to Security > Manage how I Sign in > then add your email/phone number as your verification method.
Once you're done, you will need to wait for the 30-day restriction state to complete; but, since the hacker has their email added to your account, having them in full control over your account, they can simply cancel your security info change request.
If this happens, you will need to try requesting again, and hopefully, the hacker will not notice.
Unfortunately, it is also not possible to bypass the 30-day restriction state.
If the 30-day restriction state is complete, you will be able to remove the hacker's security info email from your account using your newly added security info.
However, if you can't access your account via account.microsoft.com, then the only way to recover a hacked account is through the official Microsoft troubleshooter guide:
If the account recovery web form doesn't work, and since the security info has been replaced by the hacker, I'm afraid there is no other working method to recover the Microsoft account, and Microsoft Support cannot help either.
Lastly, I would recommend reaching out to Minecraft Support regarding your Minecraft account if they can provide an alternative option:
https://help.minecraft.net/hc/en-us/request/new?ticket_form_id=360001225811
Thank you for your understanding.
Best regards,
Darhyl