No, it's because the SCTs in the certificate have invalid signatures.
I wonder if we should be doing some basic sanity checks on newly obtained certificates in Caddy, and treat this as a failure, and try the next configured CA instead.
(Obviously SCT signatures will require some external resource so we would have to weigh that a bit more, maybe make it configurable...)
Issue opened here to discuss, though it does sound troublesome/tedious: https://github.com/caddyserver/certmagic/issues/240