WebAuthn fixes this. You cannot give a password to a scam site, because there is no password and the authentication token is tied to the original site.
I just tested and it worked with my iPad and TouchId.
I just tested and it worked with my iPad and TouchId.