That moment where they got scammed by a hacked frontend was when I realised they were extremely incompetent and told everyone to get their funds out immediately.
Moving millions of dollars customer funds around via a browser wallet is insanely bad, they should have had well tested scripts that interact with the smart contracts directly.