You give your keys to an application or a website, that application or website IS you.
They can then just do anything, including pretending it didn't see your followers list, creating a new one with your new follower and re-publishing the list with just 1 entry.
Using remote signers like getAlby on desktop, Amber on android, etc. you take back control albeit at the consequence of more button clicks to do something.
You can auto approve things like adding likes, zapping, or whatever you do often, and everything else it will pop up, show you what it's doing and you can inspect it before you approve it.
This way you have a second layer of defence to prevent bugs like this having a worse impact on your nostr experience.