A QR code hides its destination. Your eyes cannot read where it leads until the phone processes it. That is what makes QR codes so handy and so dangerous at once: one sticker placed over a real QR code can send you to a fake payment page or a malicious app download.
Why public QR codes are risky
Attackers stick a fake QR sticker over the real one on a parking sign, a restaurant table, or a donation box. The victim scans it, sees a page that looks legitimate, then pays into the attacker's wallet or enters credentials. Because a QR does not reveal its URL before scanning, caution has to come before the scan, not after.
Practical steps to use QR codes safely
Work from a visual check to a final decision. Each step takes only seconds.
1. Inspect the QR visually before scanning
Look for a sticker placed over the QR, whether the surface is smooth, and whether it is printed with the official poster or seems added later. A sticker that sits slightly crooked or is a different material is a sign the QR was covered.
2. Use a scanner that shows the destination URL
Use the built-in camera or a scanner app that displays the destination address before opening it. Avoid scanners that forward straight to the browser without showing the link. The URL gives you a chance to judge.
3. Assess the address before opening it
Check the domain: is it official, spelled correctly, and using https. Watch for look-alike domains with typos such as g00gle or amaz0n. If unsure, do not click. Type the official address into the browser manually instead.
4. Do not pay or log in straight from a QR
A payment or login page that appears from a QR needs a second check. Compare the recipient name and destination number with the official one. Do not enter an OTP, PIN, or credentials into a page that pops up unexpectedly from a QR.
5. For important transactions, use the official app
Pay for parking, buy tickets, or donate through an official app you already installed from the app store, not from a random QR link. Official apps verify the recipient internally and are far harder to fake.
Example: a parking QR covered by a sticker
At a parking lot, a rider scans the QR at the gate to pay. What opens is an e-wallet page with the recipient name "Official Parking" and an unfamiliar number. They pay the rate. Days later, the parking operator reports the real QR was covered by a sticker. Checking the recipient name and number, or paying through the official parking app, would have saved the money.
If you scanned a suspicious QR
Do not enter anything on the page that opened. Close the tab and, if unsure, clear the download history or force-close the app. If you did enter credentials, change the related account password from a trusted device and turn on 2FA. Watch your e-wallet and bank transactions for foreign activity.
Common mistakes to avoid
- Scanning QR codes from posters promising prizes. A free prize is a classic lure to a malicious page.
- Opening a link without reading the URL. A few seconds reading the domain can prevent a large loss.
- Sharing an OTP that a QR page requests. A legitimate service does not ask for your OTP to "verify a payment".
Frequently asked questions
Can a QR code be dangerous?
Yes. A QR only stores text, usually a URL, and the destination can be anything, including a scam page.
Which scanner is safest?
One that shows the destination URL and asks for confirmation before opening. The built-in phone camera is usually enough.
Are restaurant menu QR codes safe?
Most are safe, but still check whether a sticker has been placed over it and whether the menu domain makes sense before ordering.
Sources and further reading
Editorial note: This article is educational and defensive. QR behavior differs between payment apps. Use your provider's official guidance.

