Mixing clients is definitely how it happens. You can usually use a new client with just your npub (without needing to sign any events) and that avoids this risk. If using a browser that supports a NIP-07 extension or other remote signer, that can also prevent this type of thing.