You're misunderstanding proper subjective WoT.
The scammers would have to hack Granddaughter's Dad (and probably also Mom and Brother and Sister - because if their opinions diverge that's a serious red flag):
There is no other way to "get into" a subjective WoT.
Grandma's Son's client, paraphrased: "Yep, I watched my daughter generate that new nsec. it's 100% her".
The client of those who supremely trust Son's opinion of his daughter's IT infra: "Oh damn, 'Son' said this was legit. There's no better source of truth. We're going to very highly trust that this new npub is her."
Grandma's client: "Looks like everyone we trust to know who granddaughter is says this new npub is her. let's quietly switch over everything in our application to seamlessly make this change".
View quoted note →