If you want to be safe from phishing, there is only one advice which is always good: don't enter confidential info if you did not initiate contact. Don't tell your credit card numbers to people who called you, find their phone number somewhere and call back. Don't enter your bank credentials after clicking the ad (or scanning QR code) - open a new tab and enter bank's URL (or use bookmarks).
Doubly so with how often 2fa or webauth is the norm on anything of note. In what situations would someone scan a random QR code and be like "yeah I should log in with my banking information here". Or, "wow this QR code asked me to install a random APK for my bank, sounds legit".
They're obviously not going to trick HN readers. But the general public is not so savvy.