Details, in case it's helpful/interesting to anyone: https://keybase.io/docs/api/1.0/call/login . Also of note, the hashing is done client side, not server-side.
Meme reference aside, this is actually a sane way to do things.
IMHO, MITM would be better defended against using HSTS, certificate pinning, and perhaps DNSSEC.
I assume the extra client-side hashing is done to keep the plaintext passwords out of the application memory, not protect it in transit.
To clarify, this is just an assumption. I have not read up on the topic nor do I claim to be a security expert. This is just what came to mind when I had the same thought as you.
Anyone else know for sure?