QR Code Security: Real Risks and How to Protect Yourself

Published: 11 September 2026 | Reading time: 6 minutes

Strip away the headlines and the security problem with QR codes is one sentence long: a QR code is a link you cannot read before you follow it. There is no malware inside a QR code, no tracking beacon, no way for the pattern itself to reach into your phone. The risk is entirely that the destination is not what you expected.

That is a real risk, worth taking seriously in specific situations. It is also far narrower than the "never scan another QR code again" genre of coverage suggests.

What a QR code can and cannot do

A code is a passive container of text. Scanning one does exactly four things: open a URL, add a contact, join a WiFi network, or prefill something — a message, an email, a payment form.

It cannot install software. At worst it opens a link to a download page, and every mainstream phone requires deliberate confirmation before anything installs. It cannot read your contacts, location or photo library, and it cannot execute code. A dynamic code's redirect server sees your IP address and user agent, as any web server does, but the pattern itself transmits nothing.

The one genuine exception: malformed payloads have occasionally crashed or exploited buggy third-party scanner apps. That is a flaw in the app's parser, not in QR, and it is a good argument for using your phone's built-in camera.

The risks that actually occur

Malicious URLs and quishing

The most common real attack is a code that leads to a phishing page. In email-borne versions — "quishing" — the QR image slips past scanners that inspect text for suspicious links, which is the entire reason attackers use it. Several national cyber agencies and security vendors have published advisories since around 2022. The advice is identical to email phishing: check the domain before you enter anything.

Overlay and replacement attacks

Someone prints a sticker with their own code and places it over a legitimate one: a parking meter, a restaurant table, a lobby poster. It works because the victim has no reason to suspect the venue's own code. The tell is almost always physical rather than digital — a slightly different white, a second visible edge, a code sitting off-square against the surrounding design.

WiFi codes that give away more than intended

A WiFi QR code contains the network password in plaintext. That is the format; there is no way around it. Encoding your main network password and printing it on a wall sign means anyone who walks in has it — guest networks exist for this. The inverse attack also happens: a code that joins you to an attacker-controlled network with a plausible name, after which anything unencrypted on that connection is fair game.

Payment redirection

A swapped EPC or invoice code, or a legitimate code with an altered amount, is the highest-consequence variant because money moves. The protection sits outside the QR code entirely: your banking app shows the payee name and amount before you authorise anything. Always confirm there.

Induced downloads and credential pages

A code that insists you install an app to continue, or presents a login form for a service you were not expecting, is a phishing page with extra steps. The QR part is incidental.

Your camera already does more than you think

Both iOS and Android show a preview of the resolved URL before opening it — a banner in the iPhone camera app, a card in Google Lens and most Android camera apps — and you have to tap to proceed. That preview is your entire window to make a judgement.

Be clear about what it is not. The preview shows you a string; it does not verify it, and neither Apple nor Google is vouching for the destination. The second layer — Safari and Chrome both check pages against Google Safe Browsing and warn about known phishing sites — catches known-bad destinations and nothing new.

So: the preview is a chance to read, not a guarantee. Read the domain, character by character, before you tap.

Risk, how to spot it, what to do

Risk How to spot it What to do
Sticker placed over a real code Raised edges, a second visible layer, off-square alignment, a white that does not match the card Do not scan. Tell the venue. Pay or order another way.
Lookalike domain (paypa1.com, yourbank-secure.co) Read the preview domain slowly; check the ending, not just the start Close it and type the address yourself
Unsolicited code in an email or a flyer through the door You did not ask for it; urgency in the accompanying text Treat exactly like a phishing email. Delete it.
Rogue WiFi network The preview shows the network name before you join; check it against what staff told you Confirm with a person. Never do banking on a network you cannot verify.
Payment with a wrong payee or amount Your banking app shows the name and amount before you approve Verify in the bank app, not in the code. Abort if anything is off.
Unrecognisable shortened link The preview shows a short domain you do not know, hiding the real destination Only proceed if you recognise the short domain. Otherwise skip it.
Page demands an app install to continue Any flow that blocks you until you install something Back out and find the official site yourself
Login or card form on the landing page The page looks official but the domain in the address bar is not Check the domain before typing. Never enter credentials after scanning in public.

What businesses should actually do

If you print codes for customers, you own the problem of them being replaced. The mitigations are cheap and mostly physical:

  1. Use tamper-evident labels. "Void" stock that shreds or leaves residue when lifted costs a fraction of a cent more and makes a silent swap impossible.
  2. Laminate over the code, not under it. A sticker on a glossy laminated surface shows air bubbles and edge lift — visibly a second layer.
  3. Integrate the code into the artwork. Inside a branded frame or pattern, a plain white replacement sticker matches nothing around it.
  4. Use your own short domain. A branded link is recognisable in the camera preview at a glance, the only moment that matters. It also lets you change vendors without reprinting — see static vs dynamic QR codes.
  5. Inspect on a schedule. Put it on the opening or closing checklist. Five seconds per code, weekly, catches nearly everything.
  6. Avoid unobserved spots. Ankle height, dark alcoves, back corridors. Anything in staff's line of sight is self-policing.
  7. Make payment codes single-use. A per-invoice code with a unique reference can be verified and voided. A static payment code on a poster cannot.

Where the fear is overblown

Scanning a QR code cannot compromise your device. It cannot reveal your location, contacts or messages. There is no scenario in which the pattern itself attacks you — the worst case is indistinguishable from clicking a bad link, which is a risk you manage dozens of times a day.

The contexts that deserve caution are narrow: codes on unattended public fixtures, codes in unsolicited email, and any code in a payment flow. Slow down and read the domain in those three cases. Everywhere else, scanning a menu carries about as much risk as opening a website.

Frequently asked questions

Can scanning a QR code hack my phone?

No. A code is inert text. The only realistic path to harm is following it to a malicious website, and then only if you enter information or install something. Keep your phone's operating system updated and use the built-in camera rather than a third-party scanner app, and the residual risk is very small.

Can a QR code track my location?

The code cannot. A dynamic code's redirect server sees your IP address when the scan resolves, which gives an approximate location — the same as any website you visit. A static code that contains only data, such as a WiFi credential or a vCard, involves no server at all.

Does my phone warn me if a code is dangerous?

It shows you the destination in a preview, which lets you judge for yourself. It does not certify the link. Browsers add a second layer — Chrome and Safari check pages against Google Safe Browsing and warn about known phishing sites — but that only covers destinations already reported.

Are dedicated scanner apps safer than the camera?

Generally the opposite. Third-party scanner apps are the component that has historically had parsing vulnerabilities, and many show adverts or log scans. Your phone's built-in camera is maintained by the OS vendor and previews the destination. Use it.

Is it safe to scan the QR code on a restaurant table?

Almost always, and the result tells you immediately: if it opens a menu, it was a menu. Apply the checks above if the code looks like a sticker on top of something, or if the page asks for a card number. Ordering through a table code should never require card details before you have chosen anything.

Can a QR code steal my WiFi password?

It cannot steal it, but a WiFi code contains the password in plaintext, so printing one is publishing that password. Only ever encode a guest network, and rotate the guest password if a printed code goes missing. Our WiFi QR generator flags this in the form.

What should I do if I find a code stuck over another code?

Do not scan it. Take a photo, tell the staff, and if it is a payment point or parking meter, consider reporting it — these attacks target the next person, not you.

Does error correction level help against tampering?

No, and it is worth being precise about why. Error correction reconstructs your data when the pattern is damaged. If an attacker replaces the code, the scanner reads their valid, internally consistent data perfectly. Nothing detects the swap at the QR level — which is why the mitigations are physical. See how error correction actually works.