๐ What We'll Cover
How Crypto QR Scam Volume Is Growing
Crypto fraud is a fast-growing problem, and QR codes are becoming one of the primary delivery mechanisms. The FBI's Internet Crime Complaint Center (IC3) reported that crypto-related fraud losses reached $5.6 billion in 2023 โ a 45% increase over the previous year. Within that total, QR code fraud specifically saw an increase of over 300% year-over-year, according to the FBI's 2023 IC3 report and supplemental alerts.
The mechanics are brutally simple. A scammer prints a sticker with their own wallet QR code. They paste it over a legitimate QR code on an ATM, a point-of-sale terminal, a donation box, or even a printed invoice. The sticker is thin โ about 1mm โ and blends in at a glance. The victim scans the code, sends crypto, and the money lands in the scammer's wallet. The transaction is irreversible by design.
This isn't a theoretical attack. The FBI, FTC, and multiple state attorney generals have issued consumer warnings about QR code tampering at physical locations. In 2024, the Better Business Bureau reported a surge in "QR code phishing" โ dubbed quishing โ with complaints up over 400% from the prior year.
Why QR codes? Because they bypass the number-one friction point in crypto transactions: typing a 42-character wallet address on a phone. A QR code is scan-and-go. That convenience is also the vulnerability.
The "QR Swap" Attack
The QR swap attack is the most common, lowest-tech, and hardest-to-detect crypto scam in the wild. Here is exactly how it works:
- The target: Any physical location with a publicly displayed QR code for receiving crypto payments. Bitcoin ATMs, coffee shops that accept crypto, donation boxes at museums or event booths, concert merch tables, parking payment terminals, and printed invoices left on a counter.
- The setup: The scammer prints a small sticker-size QR code on glossy sticker paper. The QR code encodes the scammer's own wallet address โ typically a fresh wallet generated for the purpose, often from a swap or privacy mixer to obfuscate the trail.
- The swap: The scammer places the sticker directly over the legitimate QR code. The sticker's adhesive is thin enough that the edges are almost invisible against the original sign or terminal screen. Many victims scan without noticing anything unusual.
- The result: The victim scans the code, confirms the payment on their wallet app, and sends crypto. The funds arrive in the scammer's wallet. The victim may not notice for hours or days โ especially if the expected transaction confirmation looks similar to what they've seen before.
The QR swap is effective because it exploits trust. You see a QR code that looks official, in an expected location, and you scan without a second thought. The scam doesn't require hacking, phishing links, or malware. It's a physical attack on a digital transaction, and that makes it invisible to antivirus software, wallet security features, and exchange safeguards.
Fake Wallet Addresses via Tampered QR Codes
Beyond physical sticker swaps, attackers tamper with QR codes in purely digital environments. The end goal is the same: you scan a code that encodes the attacker's wallet address, not yours or the merchant's.
Compromised QR generator websites. Scammers register domains that look like legitimate QR code generators: qr-generator.net, qr-code-maker.io, crypto-qr-gen.com. These sites generate QR codes that look normal but encode the scammer's wallet address. Some of these sites are even promoted via Google Ads โ paid advertisements that appear at the top of search results for "crypto QR code generator." A legitimate business that uses one of these tools to generate a payment QR code is unknowingly giving its customers a code that sends funds to the scammer.
Clipboard hijacking malware. Some malware monitors the clipboard for crypto wallet addresses. When you copy a wallet address (e.g., from an invoice or exchange withdrawal page), the malware replaces it with the attacker's address. If you paste that address into a QR generator, the resulting QR code encodes the attacker's wallet. The malware can also replace addresses in the wallet app's send field directly โ you paste, it swaps, and you send to the wrong address. Always double-check the last 4 characters of the address you're sending to, even if you copied it yourself.
Phishing emails with payment QR codes. An email arrives: "Your subscription renewal is due. Scan the QR code below to pay with crypto." The QR code encodes the scammer's wallet. These emails often spoof legitimate companies โ your internet provider, a crypto exchange you use, a domain registrar. The scam works because the QR code format makes the attack hard to analyze: a wallet address inside a QR code is invisible until scanned, and by then the damage is done.
Phishing QR Codes in Email and Social Media
QR codes in emails and social media DMs are a rapidly growing attack vector. The security industry has a name for this variant: quishing (QR + phishing).
Here is the typical quishing flow:
- You receive an email that appears to be from a crypto exchange (Coinbase, Binance, Kraken), a wallet provider (MetaMask, Phantom, Ledger), or a DeFi platform you use.
- The subject line creates urgency: "Your wallet has been compromised โ verify now to secure your funds," "Unusual login detected โ scan to review," or "Withdrawal pending โ scan to confirm."
- The email body contains a QR code โ not a clickable link, just a QR code. This is deliberate. QR codes bypass email security filters that scan text and URLs. Many email gateways cannot decode QR code images, so the attack passes straight through.
- The QR code leads to a fake wallet interface โ a page that looks identical to the real wallet provider's site but is a phishing proxy. The fake page asks you to enter your seed phrase, private key, or to "connect" your wallet via WalletConnect (actually a malicious dApp that drains your wallet).
- You enter your seed phrase or approve the connection. Within minutes, your entire wallet is drained.
Social media is another vector. Scammers post QR codes in Twitter replies, Reddit threads, Discord DMs, and Telegram groups. The pretext varies: "Free airdrop โ scan to claim," "Verify your wallet for the whitelist," "Exclusive NFT mint โ scan the QR to access." These are all variations of the same attack: scan the code, connect your wallet, approve a malicious contract, and your assets are gone.
How to Verify Before Sending
Verifying a QR code before you send crypto takes 30 seconds and can save you thousands of dollars. Here is the verification process, in order of importance:
1. Compare the wallet address โ first 4 and last 4 characters
When you scan a QR code in your wallet app, the app displays the decoded wallet address before you confirm the transaction. Read it. Compare it to the expected address. You don't need to check all 42 characters โ check the first 4 and the last 4. Scammers cannot generate a wallet address that matches both the start and end of your intended recipient's address (that would require generating billions of keys and checking each one). A mismatch in the first 4 or last 4 characters is 99.99% confirmation of a scam.
2. Use a QR scanner that shows raw text before redirecting
Most phone cameras scan QR codes and immediately open a URL without showing you the underlying text. Use a dedicated QR scanner app (like QR Scanner or Kaspersky QR Scanner) that displays the decoded content before taking any action. If the QR code decodes to a wallet address, you'll see the address in plain text. If it decodes to a URL, you'll see the full URL โ and can check whether it matches the expected domain before your browser loads it.
3. Always verify on a hardware wallet screen
If you use a hardware wallet (Ledger, Trezor, KeepKey, Coldcard), the device screen shows the destination address and the amount before you confirm. This is the entire point of a hardware wallet โ the screen is controlled by the device's firmware, not by your computer or phone. Even if your computer has malware that replaces addresses in the wallet app's display, the hardware wallet screen shows the real destination. Always verify the address on the device screen, not on your computer monitor.
7 Red Flags Checklist
Print this checklist. Keep it next to your computer. Review it before every crypto transaction that involves a QR code.
| # | Red Flag | What to Do |
|---|---|---|
| 1 | QR code is a sticker over an existing code โ the sticker is slightly off-center, has a different finish (glossy vs matte), or the edges are visible when you look closely | Peel the sticker gently. If there's a QR code underneath, the sticker is a swap. Do not scan. |
| 2 | QR code received via unsolicited email or DM โ you weren't expecting it, and it asks you to scan to "secure" or "verify" your wallet | Delete the email. Block the sender. Do not scan. |
| 3 | URL in the QR code doesn't match the expected domain โ the sticker says "Coinbase" but the decoded URL is co1nbase-verify.xyz | Use a QR scanner that shows the URL before opening it. Compare the domain character by character. |
| 4 | "Urgent" language โ "Scan now or lose your funds," "Your wallet will be disabled in 24 hours," "Immediate action required" | Urgency is the hallmark of phishing. Legitimate platforms send informational emails without QR codes. Ignore the urgency. |
| 5 | QR code asks for your seed phrase or private key โ the page you land on requests your 12/24-word seed phrase, your private key, or your keystore file | Close the page immediately. No legitimate service ever asks for your seed phrase. Period. |
| 6 | QR code came from a website you don't recognize โ you searched "crypto QR code generator" and clicked a sponsored ad or a link on a forum | Use a known, trusted QR generator. Bookmark it. Never Google-search "crypto QR generator" โ the top results may be malicious ads. |
| 7 | QR code at a physical location looks newer or cleaner than surrounding materials โ the code is bright white while the sign is faded, or the sticker has no scuffs or dust while the machine around it is worn | Look for signs of tampering. Ask an employee if the QR code is theirs. If unsure, don't scan โ ask for a wallet address to type manually. |
If any one of these flags is present, do not scan the QR code. If multiple flags are present, the scan is almost certainly malicious.
What to Do If You Scan a Scam Code
If you scanned a QR code and suspect it was malicious, your next steps depend on what you did after scanning.
If you have NOT entered your seed phrase or sent funds:
You are safe from wallet drain but may have visited a phishing site that dropped a tracking cookie or attempted a browser exploit. Clear your browser cache and cookies. Revoke any wallet connections you approved (use a revoke tool like Revoke.cash or Etherscan's Token Approvals). Change your email password if you entered it on the phishing page. You caught it in time.
If you already sent crypto to a scammer's address:
- Report to the exchange you withdrew from. Most centralized exchanges (Coinbase, Kraken, Binance, etc.) have a fraud reporting process. They cannot reverse the transaction, but they can flag the recipient address. If the scammer deposits the stolen funds to that exchange, the exchange can freeze the account.
- File an IC3 complaint with the FBI. Go to ic3.gov and submit a detailed complaint. Include: the scammer's wallet address (the one you sent to), the transaction ID (TXID), the amount and cryptocurrency, the date and time, and any evidence (screenshots of the QR code, the location, any communication with the scammer). The IC3 feeds data to blockchain analytics firms and law enforcement.
- Report to blockchain analytics platforms. Submit the scammer's address to Chainalysis (via their Sanctioned Address submission), TRM Labs, or CipherTrace. These firms maintain databases of malicious addresses that exchanges and wallet providers check against. Reporting helps prevent future victims.
- Post on-chain alerts. Use services like Etherscan's "Report a Scam" or BitcoinTalk's "Scam Alert" board to publicly tag the address as malicious. Other users who search the address before sending will see your warning.
- Monitor the scammer's wallet. Set up an alert on Etherscan or a similar block explorer for the scammer's address. If the funds move to an exchange, you may be able to identify the exchange and provide the TXID to their compliance team.
Prevention: Tools and Habits That Keep You Safe
Prevention is better than detection, and much cheaper than recovery. Here are the habits and tools that will protect you from crypto QR code scams:
Use a wallet with address whitelisting
Most modern wallets (MetaMask, Phantom, Trust Wallet, Ledger Live) support address whitelisting. Add your common send addresses to the whitelist. When a QR code decodes to an address that isn't whitelisted, the wallet can warn you or even block the transaction. This single feature prevents QR swap attacks, clipboard hijacking, and most phishing scams that rely on altered destination addresses.
Enable 2FA on everything
Two-factor authentication won't prevent a QR swap (the scammer doesn't need your login), but it will prevent an attacker who steals your seed phrase from accessing your exchange account. Use hardware-based 2FA (YubiKey, Ledger) or an authenticator app. SMS 2FA is better than nothing but is vulnerable to SIM-swap attacks.
Bookmark your QR generator tool โ never Google-search it
Scammers buy Google Ads for keywords like "crypto QR code generator," "Bitcoin QR code maker," and "wallet address QR generator." These ads appear at the top of search results, above legitimate results. Clicking one leads to a site that generates QR codes encoding the scammer's wallet address. The fix is simple: use a trustworthy QR generator that processes everything in your browser (no data sent to a server), and bookmark it. Our Crypto QR Code Generator runs entirely in your browser โ you generate the QR code locally, and your wallet address never touches any server.
Inspect physical QR codes before scanning
Run your fingernail over the edge of the QR code. If it lifts, it's a sticker. Compare the look and feel of the QR code with the surface it's on โ a glossy sticker on a matte sign is a red flag. If the QR code is on a payment terminal screen, ask the merchant to refresh the display (which clears any overlay). If you're at an event or business, ask an employee to confirm the QR code is theirs. Every second you spend verifying is a second a scammer doesn't want you to spend.
Use our browser-based QR generator
Our Crypto QR Code Generator at iluv.tools generates QR codes entirely in your browser using the qr-code-styling library. Your wallet address never leaves your device โ no data is sent to any server, no logs are kept, and no third party sees what you generate. This is the safest way to create a crypto payment QR code for invoices, donation pages, or point-of-sale displays.
Need a safe crypto QR code generator?
Generate Crypto QR Code โ