Encryption already covers interception
HTTPS encrypts content between your device and the site, so another device on the same network sees destinations and timing, not page contents or what you typed. Your private key never travels anywhere in any case.
This is why passive sniffing is not the primary concern it was a decade ago.
DNS and captive-portal manipulation
A hostile network can answer DNS queries with its own addresses, sending you to a clone of a site you typed correctly. Captive portals normalise clicking through certificate warnings, which trains exactly the wrong instinct.
A browser that enforces encrypted DNS, and a refusal to dismiss certificate warnings, both help. A reputable VPN moves the trust from the local network to the VPN provider, which is an improvement when the local network is unknown.
A VPN moves the trust rather than removing it. The network operator can no longer observe or redirect your traffic, and the VPN provider now can. That is usually the better trade on an unknown network, and a worse one if the provider is free and unaccountable.
The physical risks are underrated
Someone can see your screen, your approval prompt and your device passcode. A phone left unlocked on a table is a complete compromise with no technology involved at all.
Shoulder surfing is far more likely in a busy public place than a network attack.
A workable rule
Routine checking of balances on public Wi-Fi is fine. Signing meaningful transactions is better done on a network and in a setting you control, mostly for the physical reasons rather than the network ones.
Never enter a recovery phrase in public under any circumstances, on any network.