> How could the attestation help here?
By proving that when the user clicked "Yes, I want this loan, $X deposited on amount Y" that is actually what was on the screen then the user clicked approve. In other words, that the agreement is actually what the REMOTE party believes it is, even if the owner installed "Free coins in the bunny casino v7.0.apk" from a website.
(meaning that is not currently very provable, and exploited by scammers quite a bit. Courts have a nasty irritating habit of holding the more powerful party (ie. the bank/government) responsible for the consequences of scammers' actions. Well, at least from the viewpoint of banks/governments that is a nasty habit)