Are QR Codes Safe? How to Spot a Malicious QR Code
A QR code is just a link in disguise. Most are harmless, but a few are traps. Here is how to scan safely and spot a malicious code.
QR codes had a reputation problem for a while: "are they safe?" The honest answer is that a QR code is neither safe nor dangerous — it is just a way to deliver text, usually a link. The safety question is really about where that link goes. This article explains how malicious QR codes work and how to protect yourself when scanning.
What a QR code actually does
When you scan a QR code, your phone decodes the text inside and offers an action: open a URL, join a Wi-Fi network, save a contact. For a URL code, that means the code can send you to any web page — including a malicious one. The code itself is not the threat; the destination is.
This is the same risk as clicking a link in an email or a text. QR codes just hide the link behind a dot pattern, so you cannot see where you are going before you scan.
How malicious QR codes work
Phishing pages
A sticker placed over a legitimate code — on a parking meter, a restaurant table, a poster — redirects you to a fake login or payment page that steals your credentials. This is the most common attack.
Malicious app installs
On older or misconfigured Android devices, a code can prompt an app install. Modern phones warn before installing anything, but the risk exists on outdated devices.
Payment redirects
A code that looks like a payment or donation link can send money to the wrong account. Always verify the destination before paying.
How to scan safely
- Preview the URL before tapping. Modern phones show the link and ask you to confirm before opening it. Read it.
- Look for HTTPS. A legitimate site handling logins or payments uses https://. Plain http:// is a red flag.
- Check the domain. A phishing page may look like your bank but live at a slightly-off domain like paypa1.com.
- Be wary of codes in public places that look tampered with — a sticker placed over a printed code is a classic attack.
- Never enter passwords or payment details on a page you reached by scanning a code you did not expect.
The single best habit: read the URL your phone shows before you tap open. If it looks wrong, do not tap.
Context is the best defense
A code on a restaurant's own table tent, printed by the restaurant, is low risk. A sticker slapped on top of a parking meter is high risk. Ask yourself whether the code belongs where it is and whether the action it prompts makes sense.
If a code promises something too good — a free gift, a prize, an urgent payment demand — treat it with suspicion. Scarcity and urgency are social-engineering staples.
What about Wi-Fi and contact codes?
Wi-Fi and vCard codes are lower risk than URL codes because they do not send you to a web page. A Wi-Fi code connects you to a network (still verify the network name makes sense), and a vCard code saves a contact. They cannot phish you directly, though a malicious Wi-Fi network could monitor traffic — so prefer networks you trust.
If you create QR codes
If you generate codes for your business, you have a responsibility to your customers. Use static codes pointing at URLs you control, so no third party can change the destination. Keep your destination pages on HTTPS. And never print codes that route through services you do not trust.
A static code is actually safer for your customers than a dynamic one: because the destination is baked in, no one can swap it later. The code your customer scans is the code you printed.
Phone settings that help
Most modern phones show a preview of the URL and require a tap before opening it. Keep this behavior on — do not install "auto-open" scanner apps that bypass the confirmation. The confirmation step is your chance to spot a bad link.
Keep your phone's operating system updated. Security fixes for browser and app vulnerabilities are delivered through updates, and an outdated phone is more vulnerable to malicious redirects.
What to do if you scanned a bad code
If you tapped through to a suspicious page, close the browser tab immediately. If you entered a password, change it from a device you trust. If you entered payment details, contact your bank. Run a malware scan if your phone offers one. The faster you act, the less damage an attack can do.
The balanced view
QR codes are not inherently dangerous. Billions of safe scans happen every day — menus, payments, tickets, Wi-Fi. The risk is small and manageable if you apply the same caution you already use with links in emails: read the destination, check the domain, and do not enter sensitive data on pages you did not expect to reach.
Scan confidently, but scan attentively. A two-second URL check is all it takes to stay safe.
Try it yourself
Generate the code from this article in your browser — free, no sign-up.
Frequently asked questions
Can a QR code hack my phone just by scanning it?
No. Scanning only decodes text and offers an action. The risk is in the destination — a phishing page or malicious link — not the scan itself. Reading the URL before tapping prevents most attacks.
How do I know if a QR code is safe to scan?
Check the context (does the code belong where it is?), preview the URL your phone shows, look for HTTPS, and verify the domain. Be wary of stickers placed over printed codes.
Are Wi-Fi QR codes safe?
Mostly. They connect you to a network rather than sending you to a web page, so they cannot phish you directly. Still, prefer networks you trust, since a malicious network could monitor traffic.
What should I do if I scanned a suspicious code?
Close the page immediately. If you entered a password, change it from a trusted device. If you entered payment details, contact your bank. Acting fast limits the damage.
Are static QR codes safer than dynamic ones?
For the person scanning, yes — a static code's destination is baked in and cannot be swapped later by a third party. The code your customer scans is exactly the one you printed.