If two nodes are killed at the same time, they have no chance to do failover, so messages stay with their own node. If node 1 is started up again, it only loads its messages and won't touch the other node's. It's understandable because node1 has no way to know the status of node 2 and therefore cannot justify for a failover from it.
The failover can happens only when a live node receives member lost event. So if all the nodes in a cluster crashed at the same time, it's not possible for the failover to happen.