Nice hack. The real problem is not WhatsApp or the Unicode reverse character, though, it’s that URLs are hard. Just this simple visa.securesite.com fools a lot of people. And I don’t see a good solution in the near future.
This specific example is poor sanitization because it actively misleads the users who try to understand what they’re clicking on. Your example of the generic confusion around host names and domains is a harder problem but people have tried to mitigate it somewhat by doing things like highlighting the domain name portion. Like most phishing techniques, passkeys will end it eventually.
This assumes passkeys will be widely adopted. And that users will know to stop wherever the passkey doesn't work. I have doubts about both.