Yeah you have to be careful, I evaluate all new sites with a sand-boxed browser. That way if they install any malware it stays in the sandboxed fake home directory and dies when I kill the browser (hopefully)
There's no way I'd click on anything like that in a browser I use for anything important.
Some of the tactics they use to steal your keys are very obvious but they must work, people see free and abandon all common sense.