Are QR Codes Safe to Scan? The Real Risk
Short answer
Scanning a QR code cannot by itself install anything or compromise your phone, because a code only carries text, usually a web address. The risk is the destination, so read the domain in the preview before tapping, and be sceptical of codes on stickers in public places, where fraudsters cover the real one.
On this page
A QR code is a picture of text. That is the entire mechanism. The black squares encode a string of characters, your camera decodes it, and your phone offers to do something with the result.
A picture of text cannot execute code on your phone. The scare headlines about QR codes installing malware are describing something else: a code containing a link, a person tapping that link, and a convincing fake page at the other end. The code is the delivery envelope, not the payload.
What a code can and cannot do
| Can | Cannot |
|---|---|
| Open a web page | Install an app silently |
| Pre-fill a text message or phone number | Access your photos or contacts |
| Join a named Wi-Fi network | Read anything already on the phone |
| Add a contact card | Grant itself permissions |
| Open a payment app with amount pre-filled | Complete a payment without you |
Every entry in the left column requires you to tap a confirmation first. iOS and Android both show the destination and wait. That preview is where your decision happens, and it is the only step that matters.
The one historical exception worth mentioning: in the early 2010s a handful of QR reader apps auto-opened links without confirmation, and a few phone browsers had vulnerabilities that a crafted page could exploit. Both problems were fixed by confirmation prompts and by browsers being patched. Keeping your phone updated closes that category.
The risk that is real: sticker swaps
This is the attack that actually costs people money, and it needs no technical skill at all.
A fraudster prints a QR code sticker and places it over the legitimate one on a parking meter, an EV charger, a bike-share dock or a charity collection sign. The code leads to a convincing clone of the payment page. You pay the attacker, the meter records nothing, and you get a ticket as well.
It works because the code is unreadable to a person. You cannot tell by looking that a sticker points somewhere different from the printed code beneath it.
Defences, in order of usefulness:
- Feel the surface. A sticker over printed material has an edge you can catch with a fingernail. Peel it and see whether there is another code underneath, which is conclusive.
- Read the domain in the preview. Legitimate parking operators use their own domain. If the preview shows a shortener, a long random string, or a country code unrelated to where you are standing, stop.
- Use the operator’s own app for parking and charging. Most have one, and it removes the code from the chain entirely.
The risk that is common: quishing
Quishing is phishing with a QR code instead of a hyperlink. It shows up in emails claiming your mailbox needs reauthentication, in letters about undelivered parcels or unpaid tolls, and in posters offering free Wi-Fi.
Its advantage is not technical sophistication. It is that corporate email security scans text and links, and an image of a code is neither. The URL is invisible until the moment it is already on your personal phone, outside the filtering your employer paid for.
The tell is almost always the destination. A genuine Microsoft or Google sign-in
lives on microsoft.com or google.com, full stop. A page asking for those
credentials on any other domain is a credential harvester, whatever it looks
like. The padlock in the address bar does not contradict this, because
HTTPS proves encryption, not honesty.
Reading the preview properly
Most people glance at the preview and look for something that feels wrong. A better method takes two seconds.
Find the part of the URL immediately before the first single slash. Then read the last two segments of that part, right to left. That is the actual domain.
https://paypal.com/activity→ domain ispaypal.com. Fine.https://paypal.com.secure-login.xyz/verify→ domain issecure-login.xyz. Not fine.paypal.comhere is just a subdomain label.https://bit.ly/3xK9pQ→ domain isbit.ly. Unknowable. Treat as unknown.
Subdomains are free and unlimited. Anyone can put any brand name to the left of their own domain, and this is the single most-used trick in phishing.
Where risk is genuinely low
Proportion matters here, and the coverage of this topic tends not to be proportionate.
- Printed into a magazine, packaging or a laminated menu. Altering these requires physical access to the printing, not a sticker.
- Shown on a screen you trust, such as a till display, your own banking app, an airline check-in kiosk.
- Generated by you, for Wi-Fi sharing or contact details.
- On a product you bought, pointing at a manual or warranty page.
For these, scan and carry on. Checking the domain is still a good habit, but the realistic probability of a problem is very low.
What does not help
- QR security scanner apps. They check the URL against a blocklist and show it to you. Your phone already shows it to you, and blocklists lag new phishing domains by hours or days.
- Refusing to scan codes at all. The underlying risk is the same as clicking any link, and nobody proposes refusing to click links.
- Antivirus on the phone. The attack is a convincing web page asking you to type a password. No scanner catches that.
- Trusting the padlock. Phishing sites get free certificates in minutes.
The honest limitation
You cannot verify a code before scanning it. There is no way to know where a code leads except by decoding it, and decoding it is scanning it. The whole of your security sits in the half-second after the preview appears and before you tap.
So the practical rule is not “which codes are safe to scan” but “which pages deserve my password or card details”. Scan freely; be sceptical about what you type afterwards. If a scanned page asks you to sign in to an account you already have, close it and open that account the way you normally would — through the app or a bookmark. That habit defeats quishing entirely, and it costs about fifteen seconds.