When you connect to the domain with torbrowser, the server detects your IP, then redirects to the appropriate .onion site if coming from an exit node. In order to be MITM'd, you'd have to either be using a Tor exit node that was compromised, or my server would have to be completely compromised beforehand.
neither of these seem like likely scenarios, so I'm curious as to what you see that I don't.
However, that's not too much an issue. we don't offer binaries (outside of two pdf files that may have a jpg embedded), and nothing on our Onion site requires a download. The most they could really do is make someone give bitcoins to the wrong wallet. That's a pretty easy customer service issue to solve ("We are not responsible for bitcoins sent to wrong wallets").
I guess I'm not seeing the vulnerability here.