It very much is not. If I use cash to commit a crime but then deposit it into a KYC bank account which is then used as a side channel to get me caught does not mean its the cashes fault.
XMR privacy and anonymity can not protect you from going out of your way to convert it into inferior surveillance currency which then gets you busted.
That's basic logic and should be a obvious technical limitation.
If they've attacked it via netflow analysis, then it doesn't matter to a criminal whether or not it's a problem in the protocol because how is a criminal supposed to use it if not on the internet?
By "practical terms" I mean that a criminal sitting in prison isn't going to care whether the vulnerability that got them there was layer 7 or not. It doesn't fucking matter to them at that point.
Everything on the internet is vulnerable to netflow traffic deanonymization; it is a fundamental limitation with the design of the internet. The only thing that stops these attacks from being more common is the relative difficulty of obtaining the required data.
>Everything on the internet is vulnerable to netflow traffic deanonymization
that is not how they get busted, monero literally has protections against that like ring signature and dandelion. They get busted by leaving xmr monero ecosystem to cash out to surveillance currencies like btc or tether on a KYC CEX.
Again, the anonymity of cash (which isn't that anonymous actually but thats another topic) is useless if you deposit them into a KYC ATM.
Whether or not they've done it by breaking the protocol itself might be of academic concern but is irrelevant in practical terms.