Or by using a U2F device, which is designed to prevent spoofing.
https://security.stackexchange.com/questions/157756/mitm-att...
The security model relies on the browser validating the origin.
Domain binding protects you from fishing, but still relies on the user's computer, including the browser, being secure. So it doesn't help here.