If you create a subdomains under your trusted domain, and point those domains to IP address controlled by scammers - you bear some responsibility for the resulting mess.
The Epic claims are pure PR spin. Epic claimed
"these rumors amounted to a paid commercial smear to harm Houseparty, announcing on their Twitter account, that a million-dollar bounty was being offered to “the first individual to provide proof of such a campaign.”"
An individual offered clear proof that Epic was pointing houseparty domains to scammers who were using that to steal folks info, the exact situation users were complaining about. These are domains UNDER EPICS TOTAL CONTROL being pointed to scammers.
They now claim they still found no evidence of a campaign against houseparty users by a hacker group - and this was all a "paid smear campaign".
Who believes these PR people -seriously?
If Amazon takes payments.amazon.com and point it to Scammer IP XXX, how does that NOT create a vulnerability?