QR Safety, Scams & Exploits

QR Codes and Crypto Scams

Crypto payments rely on QR codes, and scammers exploit that. Common crypto QR scams and how to send funds safely.

Crypto and QR codes are a natural pair — wallet addresses are long and error-prone, so a scannable code is far easier than typing. But that same convenience is exactly what scammers exploit: swap the code, and your payment vanishes into a stranger's wallet with no way to get it back. Here's how QR crypto scams work and how to send safely. 🐾

Cryptocurrency payments have a property that makes fraud especially painful: they're usually irreversible. There's no bank to call, no chargeback, no undo. When you combine that finality with QR codes that no human can read at a glance, you get a scam that's simple to run and devastating to fall for. The defenses, thankfully, are concrete and learnable.

Why do crypto payments use QR codes?

A crypto wallet address is a long string of letters and numbers — easy to mistype and impossible to memorize. Encoding it in a QR code lets a sender scan it and populate the recipient field instantly and accurately. It's a genuinely good use of the technology. The problem is that you can't tell one address from another by looking, so you're trusting the code completely — and that trust is what attackers target.

With crypto, the QR code is your payment's entire destination — and the transaction can't be reversed. That combination is why verifying the address matters more here than almost anywhere else.

How do QR crypto scams work?

1. The swapped-address code

The classic attack: an attacker replaces a legitimate payment code with their own. This might be an overlay sticker on a printed donation or payment code (see QR code sticker attacks), a manipulated image on a website, or a code sent in a message. You scan it expecting to pay a merchant or friend, but the address belongs to the scammer. Your funds arrive — just at the wrong wallet, permanently.

2. Fake payment requests

You receive a QR code with an urgent story: an "invoice" to settle, a "verification" deposit, a "refund" that supposedly requires you to send first, or an investment "opportunity." Scanning and sending hands your crypto straight to the fraudster.

3. Impersonation and support scams

Scammers pose as customer support, a celebrity giveaway, or a romantic interest, then present a QR code as the way to pay, "unlock" funds, or claim a reward. The code is always the recipient's address — theirs.

4. Clipboard and malware swaps

On a compromised device, malware can detect a crypto address (or a scanned code's output) and silently substitute the attacker's address before you confirm. This is why reading the final address on the confirmation screen — not just the code — matters.

Why is crypto fraud so hard to recover from?

Traditional payments have safety nets: banks can reverse fraudulent card charges, and transfers can sometimes be recalled. Most cryptocurrency transactions have none of this. Once a transfer is confirmed on the blockchain, it's effectively final, and the pseudonymous nature of wallets makes tracing and recovery difficult. That's not a reason to fear crypto — it's a reason to verify carefully before you send, because there's rarely a second chance.

How do I verify a crypto address before sending?

A few disciplined habits defuse nearly every QR crypto scam:

CheckWhat to do
Preview the decoded addressRead the address the code produced before confirming
Compare charactersVerify the first and last several characters against a trusted copy of the address
Confirm through a second channelAsk the recipient to confirm the address by another means you trust
Check the confirmation screenMake sure the recipient shown at the final step still matches
Send a small test firstFor large amounts, send a tiny amount and confirm receipt before the rest

When you scan the code, previewing the result is essential — a scanner that lets you scan a code safely and see the decoded output first gives you the chance to read the address rather than blindly populating a payment. For the general skill of inspecting what a code contains, see QR codes and malicious URLs.

Red flags in a crypto QR request

  • Urgency and pressure — "send within the hour or lose your slot."
  • Send-first-to-receive — any request to pay in order to get a refund, prize, or larger return is a scam.
  • Unsolicited codes from support agents, giveaways, or new online acquaintances.
  • A printed payment code that looks stickered-on or altered.
  • Guaranteed returns — legitimate investments never promise them.

Practical rules for sending crypto by QR

  1. Get the address from a trusted source, ideally the recipient directly, not a forwarded image.
  2. Always read the decoded address and compare its start and end to a known-good copy.
  3. Verify large transfers out of band and with a small test payment first.
  4. Ignore urgency. No legitimate payment collapses because you took ten minutes to check.
  5. Keep your device clean and updated to reduce the risk of address-swapping malware.

If you've already sent to a scammer

Recovery is difficult, but act quickly anyway: stop any further payments, gather all evidence (the code, addresses, messages, transaction IDs), and report it to your exchange, the platform where you were contacted, and the relevant fraud authorities. Our guide on how to report a malicious QR code outlines the steps and who to notify. Reporting won't always recover funds, but it helps authorities track scammers and can protect others.

The calm bottom line

Crypto QR codes aren't dangerous by nature — they're a smart fix for unwieldy addresses. The risk is that you can't read an address by eye, and payments can't be undone. So make verification a fixed ritual: read the decoded address, confirm it independently, and never let urgency rush you. With those habits, you get the convenience of scanning without handing scammers the finality they rely on. Pair this with our broader QR code safety checklist for everyday scanning.

Frequently asked questions

Can a QR code change where my crypto goes?

The code simply encodes a wallet address, but a scammer can substitute their own code or address so your payment goes to them. Because crypto transactions are usually irreversible, reading and verifying the decoded address before confirming is essential.

How do I verify a crypto wallet address from a QR code?

Preview the decoded address before sending, then compare the first and last several characters against a copy you got from a trusted source. Confirm large transfers through a second channel and send a small test amount first when the stakes are high.

Why can't I reverse a crypto payment?

Most cryptocurrency transactions are final once confirmed on the blockchain — there's no bank or chargeback process to undo them, and wallets are pseudonymous. That finality is why verifying the recipient before sending matters far more than with card payments.

Is a "send to receive a refund" QR request a scam?

Yes, essentially always. No legitimate refund, prize, or investment requires you to send crypto first. Any request framed that way, especially with urgency and an accompanying QR code, should be treated as fraud.

What should I do if I sent crypto to a scam address?

Act fast: stop further payments, save all evidence including addresses and transaction IDs, and report to your exchange, the contact platform, and fraud authorities. Recovery is often difficult, but reporting helps track offenders and warn others.

Make a QR code the honest way 🐾

Free forever, no tracking, no expiry — generated right in your browser.

🎨 Create a QR code →