Absolutely, they are guilty, but they won't take any responsibility.
When you deploy a smart contract on a permissionless blockchain, you don't own the smart contract or the funds that it controls.
These developers are hypocrites who don't believe in the basic premises of this technology. It is easy to preach the virtues of decentralization when it makes you money and run back in the arms of daddy government when things don't play out in your favor.
They are guilty of implementing a mechanism that was broken by design, and wasting customers' money. They hadn't been hacked or stolen from - the "attacker" didn't need to hack any particular security mechanism, he was just smarter at how their market worked than the owners.