Back to Blog
Guides
July 19, 2026 3 min readBy CQRG Team

QR Code Security: How Quishing Works and How to Stay Safe

Malicious QR codes are a real and growing problem. What the attacks look like, and what both scanners and publishers should do.

A QR code is opaque by design. You cannot read it, so you cannot tell where it goes until you have already gone there. That gap is what attackers exploit, and the technique has a name: quishing, or QR phishing.

How the attacks work

The mechanics are simple. A code leads to a page that imitates a bank, a parcel service, or a payment portal, and asks for credentials or card details. Because the victim arrived by camera rather than by clicking a link in an email, the usual instinct to inspect a URL never fires.

Several patterns recur:

  • Sticker overlays. A malicious code printed on a sticker and pasted over the legitimate one; parking meters, EV chargers, and restaurant table tents are the common targets.
  • Fake invoices and letters. Posted mail imitating a utility or tax authority, with a code leading to a payment page. Physical mail carries an unearned air of legitimacy.
  • Email attachments containing codes. Used specifically because a code inside an image sails past link scanners that would catch a text URL.
  • Fake Wi-Fi codes in public places, joining the victim to an attacker-controlled network.

If you are scanning

  • Read the URL preview before opening it. Both iOS and Android show the destination first. Check the domain: not that it contains a familiar word, but that the registered domain is right. yourbank.secure-login.example.com is not your bank.
  • Feel the surface. A sticker over a printed code is usually detectable with a fingernail. On payment terminals and meters this is worth a moment.
  • Never enter credentials or card details on a page you reached by scanning. Navigate to the service yourself, through the app or a typed address.
  • Treat urgency as a warning sign. Fines, account suspensions, and delivery failures with a deadline are engineering pressure so you do not stop to check.
  • Be sceptical of codes in unsolicited mail, however official the letterhead looks.

If you are publishing codes

Your responsibilities run the other way:

  • Use a domain people recognise as yours. A redirect on your own domain is far more trustworthy than a generic shortener, and lets people verify the destination from the preview.
  • Tell people where the code goes, in text next to it. "Scan to view our menu at example.com" removes the guesswork and makes a swapped sticker easier to spot.
  • Inspect physical codes on a schedule. Anything in a public place should be checked for overlays as part of routine maintenance.
  • Never ask for credentials or payment on a page reached by scanning without an independent verification step. Doing so trains your customers into exactly the habit attackers rely on.

What we do on our side

Tracked CQRG codes redirect through a link on our domain, which makes the safety of those redirects our problem. Destinations are validated before a code is saved and re-checked at redirect time; non-web schemes and addresses pointing at private infrastructure are refused outright. Confirmed abusive links are disabled and the account removed. Report anything suspicious to our abuse address.

Stay safe

Never enter a password or card details on a page you reached by scanning a code, however urgent it looks. Open the service yourself through its app or a typed address, and check the URL preview before tapping through.

QR codes are not dangerous in themselves; the danger is that they hide the destination until you arrive. Previewing the URL before opening it defuses nearly every attack in this category.

securityphishingsafety

Ready to make a Bitcoin QR code?

Put these tips into practice in seconds, no sign-up required.

Bitcoin QR Code Generator

Read next

More from Guides.