ToolBoxOnline
Developer Tools

QR Code Scanner Security Check Before You Scan That Restaurant Menu

QR codes replaced physical menus overnight. They also created a new attack vector. How to spot malicious QR codes before they compromise your device.

QR code scannerQR securitymalicious QRphishingcybersecurity

You sit down at a restaurant, scan the QR code on the table to see the menu, and a website loads. It looks like the restaurant's menu site. You browse, order, and pay through the link. Three days later, there's a $400 charge on your credit card from a website you've never heard of.

You were QR code phished. The sticker on the table wasn't the restaurant's QR code — it was a fake one pasted on top by someone who walked in, sat down, and replaced it in under 10 seconds. QR code security isn't something most people think about, but it should be.

How QR Code Attacks Work

A QR code is just a URL encoded as a pattern of black and white squares. Your phone's camera reads the pattern, decodes the URL, and opens it — usually without showing you the full URL first. This is the vulnerability: you don't know where you're going until you're already there.

Attackers exploit this with three common techniques:

Sticker replacement: Printing a malicious QR code on a sticker and placing it over a legitimate one. Restaurants, parking meters, event posters, and public transport stops are common targets. The fake sticker looks identical to the real one — QR codes are designed to be visually indistinguishable.

URL redirection: The QR code points to a legitimate-looking shortened URL (bit.ly, tinyurl.com) that redirects to a phishing site. Your phone shows "bit.ly/2Xk9mP" in the preview — that tells you nothing about the final destination.

Homograph attacks: The URL in the QR code uses Unicode characters that look identical to Latin letters. starbucks.com with a Cyrillic 'а' instead of Latin 'a' looks identical but goes to a different domain entirely.

What a Malicious QR Code Can Do

Scanning a malicious QR code can: (1) open a phishing site that steals login credentials or payment info, (2) trigger an automatic download of malware (less common on iOS, more common on Android with "install from unknown sources" enabled), (3) compose an email or text message with pre-filled content designed to phish your contacts, (4) connect your phone to a malicious WiFi network, or (5) initiate a payment or cryptocurrency transfer if your payment app auto-fills.

How to Check Before You Scan

Look at the physical sticker: Is it a sticker on top of another sticker? Does it look newer than the surface it's on? Run your fingernail across the edge — if it lifts, it's a sticker overlay.

Preview the URL before opening: Most modern phones show a URL preview when you scan a QR code. Read it. If it's a shortened URL (bit.ly, t.co, ow.ly), be suspicious. If the domain doesn't match the business you're interacting with, don't open it.

Check the destination after opening: Look at the URL bar. Is the domain correct? Is there a padlock icon (HTTPS)? Does the page ask for permissions that make no sense (camera, contacts, location for a menu)?

Use a QR scanner that shows the full decoded content: Not all scanner apps are equal. A good one shows the raw URL before offering to open it, giving you a chance to inspect it.

For scanning QR codes safely, use our QR code scanner which shows the decoded content before opening. For generating your own legitimate QR codes, our QR code generator creates codes for URLs, WiFi, and vCards. For creating product barcodes, try our barcode generator.

Tools mentioned in this article

شارك هذه الأداة