What they copy, what they cannot, and when they catch people.
The copies are not sloppy. Assume the page in front of you is pixel identical to the real one and reason from there.
Every byte a browser renders was handed over on request. There is no secret in a stylesheet and nothing privileged in an image. Rehosting a storefront is mechanical work, and the login form functions because capturing input is easier than authenticating it.
Where the page lives. The address is derived from a private key, so a copy has to sit somewhere else by construction. That is not a policy or a safeguard, it is arithmetic, and it is the only property in this whole situation that an attacker cannot buy their way around.
Producing a key whose address opens with chosen characters costs hours for four or five of them, and thirty two times more for each one after. So a lookalike matches the opening and diverges everywhere else. Anybody checking the first few characters is checking precisely the part that was cheap to fake.
Nobody types a market name into a search engine while their bookmark works. The searches happen during outages, from people who are worried and moving fast, which is why the pages built to catch them rank for exactly those queries. Remove the search and the whole approach fails, and removing the search means keeping the address list somewhere you already have it.
Credentials typed into a copy are gone. The account is a smaller problem than the reuse: change that password anywhere else it appears, since that is where a captured pair usually gets spent. Ignore any address, contact or instruction that page supplied, and go back in through something you held before today.