You are signed in. This site just set
Set-Cookie: SESSION=sess-t738884546; HttpOnly; Secure; SameSite=Strict
Host-only cookie on bank.teiubescdalghezamea.app. No other origin can read it and no cross-site request may carry it.
Now go back to the attacker page.