NexFlow › QR code crypto scams, explained
QR code crypto scams — the attack you can't read
A QR code is a string of text rendered unreadable to you. Everything the scam needs is in that gap between what the code says and what you think it says.
The QR code's whole design is that humans can't read it. It's a 44-character wallet address, a bitcoin:/ethereum:/solana: payment URI, or a WalletConnect session string — delivered as a picture your camera resolves and you never see the contents of until the wallet fills them in. That opacity is the entire attack surface. Nothing in a QR scam is "hacked" — no cryptography is broken, no wallet is compromised. The victim performs a perfectly valid transaction to the wrong destination because the code they scanned wasn't the code they meant to scan.
The three payloads a QR can carry
A plain address or payment URI. The classic: scan, the wallet opens with recipient and sometimes amount pre-filled, you approve, funds leave to the wrong address. This is the parking-meter pattern — a sticker over the legitimate code — and its digital twin: a "refund payment" or "contribution address" QR pasted into a chat, a fake exchange email, a counterfeit invoice.
A WalletConnect or dapp-session URI. Scan it and your wallet asks to pair with a dapp. Pair with the attacker's page and it can request signatures — including ones that look harmless but authorize a drain. The code didn't steal anything; the session you approved did.
A URL — quishing. QR phishing. The code opens a cloned exchange, wallet or "airdrop claim" page asking for your seed phrase or a signature. It works in email because spam filters read links, not pictures of links.
Where the attacks actually show up
| Surface | The swap | Cost of the trick |
|---|---|---|
| Parking meters / EV chargers / vending | Sticker over the real payment QR | A printed sticker — the documented, boring version that keeps working |
| Chat / email "pay me" or refund codes | Image swapped for a QR encoding the attacker's address | Free — a QR is five minutes of work for anyone |
| "Claim your airdrop" / support DMs | Code opens a malicious WalletConnect pair or claim page | A cloned site plus the code |
| Fake "verify your wallet" prompts | QR asks for a signature that grants an approval | One approved signature can be the whole theft |
The common thread: the QR is never the exploit — it's the delivery. What it loads is what you actually have to check, and in every variant the check happens after the scan, before the approve.
Checking what the code decoded
For a payment code: the wallet shows the recipient it decoded — don't trust it blindly, because a swapped QR is exactly the attack. Compare the first and last several characters to the address you intended through a second channel (the merchant's site, a message you already have). "First 6 and last 6 match" is the standard check — full-string comparison is better, and it takes ten seconds.
For a WalletConnect or dapp QR: the wallet shows the session request's domain. Check it character-for-character — app.uniswap.org vs a look-alike — because pairing with a clone page is the whole scam. If the request asks to sign anything beyond the session itself, that's the payload arriving.
For a link QR: treat whatever it opens as hostile until proven otherwise. A page asking for a seed phrase, a private key, or an "unlock signature" is the scam itself — real services never ask for the phrase, and a code promising an airdrop that wants a signature is a drain request wearing a QR's costume. If a code drops you on a token-claim flow, run the contract through the scanner first — a honeypot-shaped contract is visible before you touch it.
The invariant: your wallet will happily send to whatever the code says. The security check isn't in the QR — it's in the pause between "scan" and "approve", reading the decoded address or session against what you meant to do.
The social-engineering layer
The physical sticker is only half the family — the other half is a person talking you into scanning. "Send me a QR of your receive address" inverts the flow: the scammer convinces you to display your address as a QR, then uses a payment-request URI to make their send-to-you look like a request you're approving. "Scan this to join the group" pairs your wallet with a dapp that immediately requests signatures. And the refund-and-support scam — "you're owed a refund, scan to process it" — is the parking-meter attack relocated to your inbox, where the sticker is replaced by a customer's trust. In every variant, the request to scan comes from the person who benefits from what the code contains.
Why this one keeps working
QR scams survive because they hit the two places crypto is weakest. First: addresses are meant to be unreadable — a long base58 or hex string that humans were never going to type, which means nobody developed the reflex of actually comparing them. Second: the code arrives in a context of trust — a sticker on the meter you always use, a "support" DM when you're already stressed, an email that looks like the exchange you have an account with. The attack borrows the trust of the surface it's pasted on. Nothing about the QR format can warn you; a code that says "here is an address" and a code that says "here is an attacker's address" are pixel-identical.
The defense isn't technical — it's a habit. Scan-and-verify instead of scan-and-send, the way you'd check the recipient on a bank transfer. The blockchain doesn't care whose address it was; the transaction settles either way.
Check the contract before the claim
If a QR landed you on a token claim or a mint you weren't expecting, run the contract before signing anything:
Frequently asked
How do QR code crypto scams work?
A QR code encodes text you can't read with your eyes — usually a wallet address or a payment URI. The scam replaces the code you meant to scan (a sticker over a real one, a swapped image in a message) so your wallet fills in the attacker's address. Nothing is hacked — you send the funds yourself, to the wrong place. Variants carry WalletConnect URIs or malicious links instead of plain addresses.
Can a QR code steal crypto by itself?
No — the code just loads data into your wallet or browser. The theft happens at the next step: a pre-filled send to the attacker's address, a WalletConnect session request to a fake dapp, a page that asks for your seed phrase or a signature. The QR is the delivery mechanism; the payload is whatever it loads. That's why the checkable moment is after scanning, before approving — read the address, read the request.
What is quishing?
QR phishing — a code that opens a credential-harvesting page instead of an address. It works because corporate mail filters can't see inside an image: the malicious link rides in as a picture, not a clickable URL. The crypto version lands you on a cloned exchange, wallet or "airdrop claim" page asking for a seed phrase or signature. Same defense as any phishing: the code is untrusted input, and what it opens is what you actually have to check.
Are QR code parking-meter scams real?
Yes — it's the documented, boring version of the attack: scam stickers placed over the real payment code on parking meters, EV chargers, vending machines and parking-gate terminals. You scan to pay a few dollars and land on a card-stealing page, or send crypto to the wrong address. The version that costs people real money is usually the least cinematic one.
How do I safely scan a crypto QR code?
Treat the code as unreadable input and check the decoded result: confirm the first and last characters of the address against the intended recipient through a second channel, verify a WalletConnect request's domain matches the dapp you meant to open, and never enter a seed phrase on a page a code opened. If the code is a physical sticker in public, assume it's hostile until the merchant confirms it's theirs.