This is a tricky thing to answer (and not because I'm investor in Safe - my stake is tiny and I couldn't care less about it relative to my reputation)
For Safes and other smart wallets to be useful, the ability to make secure signatures must exist as a complement.
Safe provides one such possibility through the centralized front end, but it should never be relied on exclusively.
I would blame Safe most for not working more with the largest and most at-risk Safe users to educate them on secure signing practices to ensure secure signing is abundant.
Secondarily, I would blame Safe for getting compromised, and I hope we eventually learn how that happened exactly.
But the reality is that
1) independent message verification for Bybit is easy and prevents almost every hack
2) perpetually preventing a frontend from becoming compromised is comparatively much harder
3) drawing attention to 2) instead of 1) prevents people from learning the right lesson, which is to adopt secure signing practices and stop trusting frontends