← all articles

QR Codes and What Scanning One Actually Does

QR codes went from a niche manufacturing tool to something you point your phone at dozens of times a week: menus, parking meters, event tickets, wifi passwords taped to a router. That jump in familiarity is exactly why they’re worth a closer look. Most people have a vague sense that scanning one might be dangerous, and no clear idea why. The actual mechanics are simple, and once you understand them, it’s easy to tell which QR codes deserve a second look and which don’t.

What a QR code actually is

A QR code is a two-dimensional barcode. Where a traditional barcode encodes a short number by varying the width of parallel lines, a QR code arranges black and white squares in a grid to encode a chunk of text, usually a few hundred characters. That text can be a URL, but it doesn’t have to be. It can also be a wifi network name and password, a contact card, a calendar event, plain text, or a payment identifier. The three squares in the corners aren’t decoration, they let a scanner figure out the code’s orientation and size before reading the data inside.

When your phone’s camera points at one, it isn’t doing anything mysterious. It’s running the same kind of pattern-recognition math a barcode scanner at a checkout counter runs, just for a denser grid. The output is a string of text, nothing more.

What actually happens when you scan one

On a modern phone, scanning a QR code with the built-in camera app produces a notification or on-screen banner showing the decoded content before anything opens. If the content is a URL, you’ll typically see the address before you tap it. If it’s wifi credentials, you’ll see a prompt to join that network. If it’s a contact card, you’ll see an offer to add a contact.

Tapping that prompt hands the decoded text to whatever app handles that type of content: a browser for a URL, the wifi settings screen for network credentials, the contacts app for a vCard. The QR code itself doesn’t run anything. It’s a container for a short piece of text, not a program, and there’s no widely documented mechanism by which decoding one on a current phone triggers code execution on its own. The pattern of squares can’t reach into your phone and do something the decoded text doesn’t ask an app to do.

That distinction matters because it tells you where to actually direct your attention. The thing worth watching is what you do with the text the code contains.

Where the risk actually lives

The specific thing QR codes change, compared to a normal link in an email or webpage, is that you lose the ability to preview the destination before committing to it. With a text link, you can hover over it (on desktop) or long-press it (on mobile) and see the URL before tapping. A QR code hides that information behind a scan. You find out where it points only after your phone has already decoded it, and by then the habit of “check before you click” has often already been skipped, because scanning feels like a single, low-stakes action.

That gap is what phishing campaigns built around QR codes (sometimes called “quishing”) rely on. A QR code pointing to a convincing but fake login page works the same way any phishing link works: the danger is in typing your credentials into a page that isn’t the real site, not in the act of scanning. QR codes also slip past some email filtering that scans link text for known bad domains, since the destination is embedded in an image rather than readable text, at least until the filter itself decodes it.

Shortened links compound this. A QR code that decodes to a bit.ly-style redirect gives you a destination you still can’t fully evaluate, because the shortener hides the final domain until you follow it.

The sticker problem

Public QR codes, the kind printed on a parking meter, a restaurant table tent, or an event poster, have a physical vulnerability that has nothing to do with software: anyone can print their own sticker and place it over the real one. Because a QR code is just an image, swapping it swaps the destination entirely, with no hacking involved. This has shown up in real reports involving parking payment machines, where a fraudulent sticker redirected payment to an attacker’s account instead of the city’s.

If you’re about to scan a code in a public space for anything involving payment, it’s worth a glance to see whether it looks like it’s sitting flush on the surface it’s printed on, or like a separate sticker slapped on top of the original signage.

Wifi QR codes specifically

A QR code that encodes wifi credentials (network name, password, and security type) will have your phone join that network automatically once you confirm the prompt. The risk here is the same as manually joining any network you don’t control: your traffic passes through whoever operates that access point. The QR code doesn’t add a new risk beyond convenience, it just removes the step of noticing the network name, which is exactly why an attacker-controlled QR code taped up in a cafe is worth being a little more deliberate about than the wifi list you’d normally scroll through.

What scanning does not do

It’s worth saying plainly: scanning a QR code does not, by itself, install malware, exfiltrate your contacts, or hand over control of your phone. The realistic incidents involving QR codes almost always require a second step where you act on the decoded content: entering a password on a spoofed page, approving a permission you didn’t mean to grant, or sending a payment to the wrong recipient. The code is the delivery mechanism, not the exploit.

Checks that don’t require paranoia

A few habits cover most of the realistic risk without turning every menu scan into an investigation:

  • Read the preview before tapping. Most camera apps show you the decoded URL or content before opening it. Actually look at it.
  • Check the domain, not just that it looks legitimate. Lookalike domains (extra letters, wrong extension) are the same trick used in email phishing.
  • Treat unsolicited codes like unsolicited links. A QR code mailed to you, emailed, or newly appearing on a public poster deserves the same skepticism as a text message with a suspicious link.
  • Glance for physical tampering on any public code tied to payment, parking, or ticketing.
  • Use your phone’s built-in scanner rather than a random third-party QR app, especially ones that ask for permissions unrelated to the camera.
  • If a code pushes you toward an urgent login or payment, slow down and reach the site independently, by typing the address you already know or opening the app you already trust, rather than following the code’s redirect.

None of this makes QR codes something to avoid. They’re a convenient way to move a chunk of text from a physical surface to your phone, and the actual mechanics are no more dangerous than typing a URL yourself. The difference is that a QR code asks you to trust a destination you can’t see until after you’ve already committed to it, so it’s worth spending the extra second to look.

If you want more of this kind of grounded, mechanics-first look at everyday privacy and security questions, check out more from The Privacy Wire.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →