Cloudflare has now disabled DNSSEC validation on their 1.1.1.1 resolver: https://www.cloudflarestatus.com/incidents/vjrk8c8w37lz
If it turns out the DNSSEC issue was caused by threat actors, this downstream effect could very well have been the reason to do it.
Welp. I think can call it on DNSSEC now.