In this case, it wasn't anything like that.
Someone exploited a weakness in CloudFlare and was able to replace the Badger website. When someone clicked on the site to execute an approval transaction, it went to the attacker first, which gave the attacker full control over their wallet.
It did take a manual step on the part of Celsius though... which should have been checked more closely. The UX around that checking is really terrible though and when someone is trying to do something quickly, they aren't always going to check. This is a big failure of wallets these days.
Balancer.fi just had a similar attack happen to them where the .fi registry allowed a nameserver change.
https://twitter.com/Balancer/status/1704552288201883809
It is also clear that the frontends really need to be hosted in a way that they can't be modified.